Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 686 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1784
Esta semana
RSS
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-48333] Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu…
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-48399] Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability th…
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-48317] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically …
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-69246] Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the req…
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable buil…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18605] A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown funct…
A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been released to t…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18606] A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is…
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has be…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-69096] OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.…
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler build…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-9390] XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed…
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor checked against the NCName grammar that XML requires of an ID, so a URI containing a single quote closes the string literal in…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18600] A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.s…
A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. Such manipulation of the argument switch leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was …
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18598] A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function …
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this d…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18599] A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread…
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of …
M Alto vulnerabilidad
03/08/2026
Vulnerabilidad de validación de entrada en módems permite denegación de servicio remota (CVE-2026-21554)
Se ha identificado una falla de validación de entrada en módems de múltiples fabricantes que permite ataques de denegación de servicio remota sin requieren privilegios adicionales. Esta vulnerabilidad afecta infraestructura alta de conectividad en empresas y proveedores de servicios en LATAM. Con puntuación CVSS 7.5, representa un riesgo elevado para la continuidad operativa de sistemas que dependen de estos dispositivos.
M Alto vulnerabilidad
03/08/2026
Vulnerabilidad de validación en módems NR permite denegación de servicio remota (CVE-2026-21548)
Se ha identificado una falla de validación de entrada impropia en módems 5G NR que permite a atacantes remotos provocar denegación de servicio. La vulnerabilidad requiere privilegios de ejecución del sistema y afecta principalmente a infraestructuras de telecomunicaciones y dispositivos IoT conectados en redes móviles de LATAM. Con CVSS 7.5, representa un riesgo significativo para operadores y empresas dependientes de conectividad 5G.
M Crítico vulnerabilidad
03/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en Wavlink WL-NU516U1 (CVE-2026-18588)
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en el enrutador Wavlink WL-NU516U1 versión 708c073-mt7628, específicamente en la función fgets del archivo nas.cgi. Un atacante remoto puede explotar la manipulación del parámetro CONTENT_LENGTH para ejecutar código arbitrario sin autenticación. Esta vulnerabilidad afecta principalmente a infraestructuras de PyMEs y centros de datos en LATAM que utilizan estos dispositivos como puntos de acceso o enrutadores en redes corporativas.
M Alto vulnerabilidad
03/08/2026
Vulnerabilidad de inyección CSV en BaserCMS afecta a sitios web en LATAM
BaserCMS contiene una vulnerabilidad de inyección de código en archivos CSV (CVSS 7.1) que permite ejecutar código malicioso cuando un usuario descarga y abre un archivo CSV manipulado. Afecta principalmente a sitios web desarrollados con esta plataforma en México y Latinoamérica. Los atacantes pueden distribuir archivos CSV maliciosos para comprometer sistemas o robar datos sensibles.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/08/2026
Vulnerabilidad alta de deserialización en PRISMAproduction 6.5 y anteriores permite ejecución remota de código
Una vulnerabilidad de deserialización en PRISMAproduction versión 6.5 o inferior permite a atacantes ejecutar código arbitrario en sistemas afectados. Con puntuación CVSS 7.5, esta falla representa un riesgo significativo para infraestructuras empresariales en México y Latinoamérica que implementen esta solución en entornos de producción. La explotación no requiere interacción del usuario y puede comprometer la integridad y confidencialidad de datos altas.
M Alto vulnerabilidad
02/08/2026
Vulnerabilidad alta en cliente OCPP 1.6: desbordamiento de buffer en parse_rpc_msg()
Se detectó una falla de seguridad en el procesamiento de marcos WAMP RPC dentro del cliente OCPP 1.6 (subsys/net/lib/ocpp). La función extract_string_field() utiliza strncpy() sin garantizar NUL-terminación, permitiendo lectura de memoria adyacente mediante campos uid y action malformados. Esto afecta sistemas de carga de vehículos eléctricos y controladores IoT en infraestructura de movilidad en Latinoamérica.
M Alto vulnerabilidad
02/08/2026
Vulnerabilidad alta de Directory Traversal en plugin CubeWP Framework para WordPress (CVE-2026-13339)
El plugin CubeWP Framework para WordPress (versiones hasta 1.1.30) contiene una vulnerabilidad de traversal de directorios en la función 'cubewp_get_svg_content' que permite a atacantes sin autenticación leer archivos arbitrarios del servidor, incluyendo credenciales de bases de datos y configuraciones sensibles. Esta vulnerabilidad afecta especialmente a sitios de e-commerce y empresariales en LATAM que utilizan este framework para gestión de contenido. Con puntuación CVSS 7.5, representa un riesgo alto para la confidencialidad de datos corporativos.
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica en ArcadeDB permite ejecución de comandos del sistema operativo
ArcadeDB versiones anteriores a 26.7.2 contiene una vulnerabilidad que permite a usuarios autenticados con permisos de UPDATE_SCHEMA crear triggers JavaScript maliciosos que ejecutan comandos del sistema operativo mediante java.lang.Runtime. Empresas en LATAM que utilizan ArcadeDB en producción para bases de datos críticas están expuestas a compromiso total del servidor si no aplican el parche inmediatamente.
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica en ArcadeDB anterior a 26.7.2 permite ejecución arbitraria de código JavaScript
ArcadeDB versiones anteriores a 26.7.2 no validan correctamente permisos de scripting en sentencias SQL DEFINE FUNCTION con lenguaje JavaScript, permitiendo que usuarios con acceso a la base de datos ejecuten código malicioso y eludir controles de seguridad. Este fallo afecta principalmente a empresas en LATAM que utilizan ArcadeDB para aplicaciones críticas sin actualizar regularmente. El CVSS 9.8 indica riesgo crítico que requiere atención inmediata.