Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
866
Esta semana
RSS
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80193] Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller…
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-76148] CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the…
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58089] When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach P…
When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58090] The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messag…
The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58091] The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If lock…
The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility. On a system with a multiple audio devices, an unprivileged local user can exploit this use-a…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-54467] On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on …
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-57170] Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc…
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template code in a non-sandboxed environment, allowing server-side template injection that can lead to arbitr…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-57171] Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc…
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without path-traversal validation, allowing arbitrary file write outside the Trestle workspace. …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-29988] A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Mil…
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames,…
M Alto vulnerabilidad
25/08/2026
Inyección de comandos alta en TOTOLIK N600R 4.3.0cu.7647_B20210106
Se detectó una vulnerabilidad de inyección de comandos en routers TOTOLINK N600R versión 4.3.0cu.7647_B20210106 a través del parámetro ntp_server en /cgi-bin/cstecgi.cgi. Un atacante remoto puede ejecutar comandos arbitrarios sin autenticación, comprometiendo completamente el dispositivo. Esta vulnerabilidad afecta especialmente a PyMEs y centros de datos en LATAM que usan estos equipos como punto de acceso o pasarela de red.
M Alto vulnerabilidad
25/08/2026
Inyección de plantillas en Compliance-trestle permite ejecución remota de código
Compliance-trestle (versiones anteriores a 3.12.4 y 4.0.0-4.0.3) contiene una vulnerabilidad de inyección de plantillas del lado del servidor en las etiquetas Jinja2 MDCleanInclude y MDSectionInclude. Un atacante puede ejecutar código arbitrario reparseando contenido Markdown no confiable como código fuente de plantilla. Afecta a organizaciones que utilizan Trestle para gestionar documentos de cumplimiento OSCAL en México y LATAM.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de replay attack en Spring Security afecta aplicaciones Java
Spring Security contiene una vulnerabilidad de caché que permite ataques de reproducción (replay) contra tokens DPoP (Demonstrating Proof-of-Possession). Un atacante puede desalojar entradas legítimas del caché mediante inundación de solicitudes, para luego reutilizar pruebas DPoP válidas interceptadas. Afecta versiones 6.5.0-6.5.11, 7.0.0-7.0.6 y 7.1.0. El riesgo es alta en sistemas de autenticación OAuth 2.0 y APIs sensibles en instituciones financieras y plataformas de gobierno digital de LATAM.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de buffer overflow en BlueZ afecta stack Bluetooth de Linux
Una vulnerabilidad de desbordamiento de búfer en la pila Bluetooth de Linux (BlueZ) permite a atacantes remotos dentro del rango de radio enviar paquetes Extended Inquiry Response (EIR) malformados que causan bloqueos del servicio bluetoothd. Afecta servidores Linux, dispositivos IoT y sistemas embebidos comunes en infraestructura LATAM, con potencial de denegación de servicio y ejecución de código remoto.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de inyección SQL en SililaWijesinghe Food Ordering System (CVE-2026-79804)
Se ha identificado una vulnerabilidad de inyección SQL en SililaWijesinghe Food Ordering System que permite manipular el parámetro 'search_box' en el archivo /search.php para ejecutar comandos SQL maliciosos de forma remota. El exploit está públicamente disponible y afecta principalmente a restaurantes y plataformas de delivery en México y Latinoamérica que utilizan este sistema. Con puntuación CVSS 7.3, representa un riesgo alto para la confidencialidad e integridad de bases de datos de clientes y transacciones.
M Alto vulnerabilidad
25/08/2026
Inyección SQL alta en Simple Inventory System 1.0 permite ejecución remota
Se identificó una vulnerabilidad de inyección SQL en Simple Inventory System 1.0 que afecta el archivo /InventoryManagement/edit.php mediante manipulación del parámetro ID. La vulnerabilidad permite a atacantes remotos ejecutar comandos SQL arbitrarios contra la base de datos del sistema, comprometiendo la integridad y confidencialidad de datos inventariales. Existe exploit público disponible, representando riesgo inminente para empresas en LATAM que utilicen este software en producción.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65183] Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix …
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes t…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65927] Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes …
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79292] Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who…
Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79286] Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a …
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79266] Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leverag…
Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)