Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1841
Esta semana
RSS
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71957] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71958] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71954] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71955] D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain …
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71948] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71949] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71950] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71951] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71952] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71953] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71944] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71945] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71946] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71947] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
Plugin AI Copilot – Content Generator para WordPress vulnerable a bypass de autorización
El plugin AI Copilot – Content Generator en WordPress (versiones hasta 1.5.6) presenta una vulnerabilidad crítica de bypass de autorización (CVSS 9.8) que permite a atacantes no autenticados crear cuentas de administrador y comprometer completamente el sitio web. Esta vulnerabilidad afecta especialmente a empresas en LATAM que utilizan WordPress para presencia digital y e-commerce.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en OpenYak permite ejecución de código remoto desde navegadores web
OpenYak, un runtime local para modelos de IA con herramientas integradas, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.3. El backend del escritorio expone una API HTTP sin validación de origen, autenticación de loopback ni enforcement de Content-Type, con política CORS abierta. Cualquier página web visitada mientras OpenYak se ejecuta puede ejecutar comandos arbitrarios en el sistema local, comprometiendo completamente la máquina del usuario.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de contaminación de prototipos en biblioteca scim-patch anterior a v0.9.1
La biblioteca scim-patch versiones anteriores a 0.9.1 es vulnerable a contaminación de prototipos (prototype pollution) al procesar operaciones SCIM PATCH con valores malformados. Un atacante puede inyectar propiedades en Object.prototype a través de claves como "__proto__.someProp", comprometiendo todos los objetos planos en el proceso Node.js afectado. Esto afecta a servicios que procesan JSON controlado por el atacante, típicamente APIs de identidad y gestión de acceso.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Kata Containers permite ejecución de código en el host
Kata Containers anterior a versión 4.0.0 es vulnerable a ejecución de código en el host mediante anotaciones de configuración sin validar. Un atacante puede especificar una ruta TOML arbitraria a través de la anotación io.katacontainers.config_path para cargar archivos maliciosos del host. Esta vulnerabilidad afecta infraestructuras containerizadas en datacenters y plataformas cloud de empresas LATAM que ejecuten orquestación con Kubernetes.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-61808] LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRA…
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitiga…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-48039] Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to…
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authenticatio…