Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1036
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-67270] Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Vali…
Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-67273] Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of S…
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-70411] Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication fo…
Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage acc…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-61411] Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Infor…
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-26287] External Secrets Operator reads information from a third-party service and automatically injects the…
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` b…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105845] Payload is a free and open source headless content management system. In versions from 3.0.0 before …
Payload is a free and open source headless content management system. In versions from 3.0.0 before 3.88.0 and canary versions before 4.0.0-canary.27, an untrusted user who can query readable collections through dynamic filters or joins can submit a request that causes SQL injection in the SQLite and Postgres adapters. This issue is fixed in versions 3.88.0 and 4.0.0-canary.27.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-63692] Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Cr…
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-67269] Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privile…
Dell Container Storage Modules (CSM) Operator, versions prior to 1.18.0 contains an Improper Privilege Management vulnerability in the ContainerStorageModule Custom Resource reconciler. A low privileged remote attacker could potentially exploit this vulnerability, leading to escalation of privileges and gaining root-level access on cluster nodes.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-54472] Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credential…
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the csm-docs. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.9.8
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-61421] Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credential…
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-63688] Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication f…
Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.
G Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105793] Vulnerabilidad Android en Android Framework - CVSS 9.1
Vulnerabilidad de seguridad en Android (Android Framework): Vulnerabilidad de seguridad en Android. CVSS: 9.1. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105796] Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP …
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after del…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105797] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored pe…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105798] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTM…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105791] Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P…
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attack…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104069] HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() wh…
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it u…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-91140] An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Prog…
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user invokes the generator.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-85523] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi…
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and Trade Inc. SambaBox allows OS Command Injection. This issue affects SambaBox: before 5.4.1.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-77178] Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host …
Oracle VM VirtualBox before 7.2.8 allows guest OS users to cause an out-of-bounds write in the host OS in pcnetReceiveNoSync in DevPCNet.cpp in the PCNet (Am79C970A) network device model.