Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2124 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84218] A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-co…
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only reje…
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad alta en Kyverno anterior a 1.16.4 expone tokens de servicio en solicitudes HTTP
Kyverno versiones anteriores a 1.16.4 adjunta automáticamente el token de la ServiceAccount del controlador de admisión a solicitudes HTTP salientes en modo apiCall sin validación explícita de autorización. Un atacante puede exfiltrar este token dirigiendo solicitudes apiCall a servidores externos o controlados, comprometiendo completamente las políticas de Kyverno y los recursos del cluster Kubernetes.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad SSRF alta en Kyverno anterior a 1.18.0 permite inyección de solicitudes HTTP
Kyverno antes de la versión 1.18.0 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en apiCall.service.url que permite a usuarios autenticados enviar peticiones HTTP arbitrarias mediante inyección de entrada controlada por el usuario a través de sustitución de variables. Los atacantes pueden comprometer servicios internos, endpoints de metadatos en la nube y direcciones loopback, con datos de respuesta reflejados en mensajes de error de admisión. Esta vulnerabilidad afecta directamente a plataformas Kubernetes en producción en LATAM.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad SSRF alta en Kyverno anterior a 1.16.2 expone recursos internos
Kyverno antes de versión 1.16.2 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la funcionalidad APICall. Un atacante con permisos de creación de políticas a nivel de namespace puede manipular el campo URL en la configuración ServiceCall para dirigir solicitudes HTTP hacia recursos internos arbitrarios, incluyendo endpoints de metadatos en la nube (169.254.169.254) o infraestructura de otros tenants. Esta vulnerabilidad afecta principalmente a empresas con Kubernetes en entornos cloud públicos (AWS, Azure, GCP) donde Kyverno gestiona políticas de seguridad.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad de autenticación faltante en AVideo permite modificar transmisiones programadas
AVideo presenta una vulnerabilidad alta (CVSS 8.2) en el módulo de transmisión en vivo que permite a atacantes no autenticados modificar el estado de transmisiones programadas mediante solicitudes POST manipuladas. Esta vulnerabilidad afecta principalmente a plataformas de streaming y educativas en LATAM que utilizan este software de código abierto. Los atacantes pueden deshabilitar o sabotear retransmisiones sin acceso previo al sistema.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad CSRF alta en AVideo permite manipulación de contenido sin consentimiento
AVideo contiene una vulnerabilidad de falsificación de solicitud entre sitios (CSRF) en plugin/API/set.json.php que permite a atacantes realizar acciones que modifican el estado del sistema mediante solicitudes GET manipuladas. Los atacantes pueden redirigir navegadores de usuarios a URLs maliciosas para eliminar videos, desactivar cuentas o modificar listas de reproducción sin interacción del usuario. Esta vulnerabilidad afecta especialmente a plataformas de contenido y educación en línea operadas en LATAM.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82957] A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the fu…
A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82397] Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parse…
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81889] elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1…
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects fsock_get_contents(), which connects to $arr['host'] and performs a second DNS resol…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81892] EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 an…
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79746] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is used against a group route, isBearerKeyAllowedForRequest grants access to the entire group as long as any single server in that group appears in the key…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79747] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authenticated non-admin user can register a server pointing at an arbitrary URL and make the hub issue server-side requests to it, with no egress filtering (no block of loopback / RFC1918 / link-local 169.254.0.…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51725] Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…
Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51730] Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…
Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51720] Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 a…
Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82801] A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the f…
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-66047] ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code…
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin …
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51679] Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows …
Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51680] Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unaut…
Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51681] Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un…
Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.