Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 26 min
Buscando: "Quest" — 2123 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
06/09/2026
[CVE-2026-86259] OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowin…
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en Bifrost HTTP transport permite ejecución de código remoto sin autenticación
Bifrost HTTP transport anterior a versión 2.0.0 permite a atacantes no autenticados cargar y ejecutar plugins maliciosos a través de POST /api/plugins cuando la autenticación de gestión está deshabilitada (configuración por defecto). El cargador de objetos compartidos descarga archivos desde URLs HTTP y los ejecuta como librerías dinámicas en Go, comprometiendo completamente servidores en infraestructuras altas de LATAM. Afecta especialmente a plataformas de integración y orquestación de datos sin hardening de seguridad.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de autenticación en Lara Dashboard anterior a v1.3.0
Lara Dashboard versiones anteriores a 1.3.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en la ruta screenshot-login que permite a atacantes no autenticados acceder como cualquier usuario registrado mediante su correo electrónico cuando APP_ENV no está configurado en producción. Explotando el endpoint GET /screenshot-login/{email}, los atacantes obtienen sesiones completamente autenticadas con acceso a administración de usuarios, configuraciones y datos sensibles. Esta falla afecta principalmente a instancias de desarrollo y staging expuestas en entornos LATAM.
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad SSRF alta en MindsDB hasta v26.1.0 permite acceso a servicios internos
MindsDB versiones hasta 26.1.0 contiene una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en el manejador de rastreo web que permite a atacantes no autenticados recuperar URLs arbitrarias. Los agresores pueden eludir controles de lista blanca explotando configuraciones vacías por defecto y acceder a servicios internos y puntos de acceso de metadatos en la nube sin autenticación. Afecta especialmente a empresas de IA/ML en LATAM que exponen MindsDB en entornos multi-tenant o híbridos.
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de SSRF sin autenticación en Webstudio ≤0.296.0
Webstudio versión 0.296.0 y anteriores contiene una vulnerabilidad Server-Side Request Forgery (SSRF) sin autenticación en las rutas proxy /cgi/image, /cgi/video y /cgi/asset cuando la variable de entorno RESIZE_ORIGIN no está configurada. Atacantes pueden suministrar URLs arbitrarias para acceder a metadatos de instancias en la nube, servicios internos y realizar reconocimiento de infraestructura. Este vector afecta directamente a empresas en LATAM que ejecutan Webstudio en entornos cloud (AWS, Azure, Google Cloud).
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86090] ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipient…
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86091] ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing …
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-82712] Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request for…
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-9317] Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that a…
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-82538] ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository…
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and b…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19534] undici's WebSocket client crashes the whole Node.js process during the opening handshake when a serv…
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeErr…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85152] undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the ca…
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-77822] IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive informa…
IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19305] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19306] IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from …
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file content…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85699] jina-ai reader contains a server-side request forgery vulnerability where URL validation is performe…
jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and return the target's response body to the attacker.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85691] MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /…
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85695] FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allow…
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85685] AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill t…
AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request parameter to copy files into the skills directory, making them accessible through the workspace skill listing.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85686] ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compa…
ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server issue requests to internal services and cloud metadata endpoints.