Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 min
Buscando: "Multiple Vendors" — 1037 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-79803] A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploita…
A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76747] Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation co…
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to expose sensitive memory contents and cause a denial of service on the device.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-76748] A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow…
A privilege escalation vulnerability exists in the API of AOS-S. Successful exploitation could allow an authenticated read-only user to escalate their privileges and gain administrative access to the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76750] Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking Clear…
Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76751] A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manag…
A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76752] Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Ne…
Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76753] A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Ma…
A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76754] A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated …
A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-79794] A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager coul…
A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76742] Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exp…
Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76743] A vulnerability have been identified in the management interface of AOS-S that could potentially all…
A vulnerability have been identified in the management interface of AOS-S that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76744] Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation co…
Buffer overflow vulnerabilities exist in the affected interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76745] Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent a…
Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-76746] An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allo…
An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-106446] Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.…
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object inst…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103009] Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information …
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103007] Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated …
Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator delegate limited role-management capability to another user, scoped to specific indic…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102406] Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data…
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102160] An operating system (OS) command injection vulnerability in CloudVision CUE backup management may al…
An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102161] An unauthenticated attacker located on an adjacent private network (or any attacker routed through a…
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.