Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2124 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en free5GC 1.4.4 permite acceso no autorizado a contexto de autenticación
free5GC, implementación de código abierto del núcleo 5G, presenta una vulnerabilidad en el componente AUSF (Authentication Server Function) en versiones 1.4.4 y anteriores. El almacenamiento inseguro de estado de autenticación por suscriptor en una estructura global permite que atacantes accedan o manipulen credenciales de usuarios. Esta vulnerabilidad afecta directamente a operadores de telecomunicaciones y proveedores de infraestructura 5G en LATAM que ejecuten free5GC en entornos de producción.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad DoS en multer permite bloqueo de event loop en Node.js
multer, middleware popular para procesar multipart/form-data en Node.js, es vulnerable a ataques de denegación de servicio (DoS). Un atacante puede enviar solicitudes HTTP especialmente diseñadas con nombres de campo malformados que fuerzan al parser a iterar arreglos sparse de tamaño máximo, bloqueando el event loop e impidiendo que la aplicación procese otras peticiones. Afecta aplicaciones web en producción que usen multer para carga de archivos, especialmente relevante en empresas LATAM con infraestructura Node.js alta.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad en mongosqld: certificados de cliente no validados correctamente
mongosqld no valida correctamente los certificados de cliente durante el handshake TLS cuando está configurado con una autoridad certificadora. Esto permite que clientes sin certificado establezcan sesiones, comprometiendo la autenticación en entornos que dependen exclusivamente de certificados para identificar usuarios. Empresas en LATAM que utilizan MongoDB BI Connector con autenticación basada en certificados están expuestas a acceso no autorizado.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en multer permite denegación de servicio en aplicaciones Node.js
multer, middleware estándar para procesar datos multipart/form-data en Node.js, contiene una vulnerabilidad que causa RangeError no controlado al recibir solicitudes especialmente crafteadas con nombres de campos numéricos malformados. Un atacante puede terminar abruptamente el proceso Node.js, afectando disponibilidad de plataformas digitales en empresas mexicanas y latinoamericanas que usan este componente en APIs de carga de archivos.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82287] Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass o…
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials are enabled. Attackers can issue credentialed cross-origin requests from any website to read analytics data, account information, and perform authenticated state-changing operations as the …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82291] HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing creden…
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries from malicious pages visited by logged-in users to access workspaces, projects, forms, submissions, and respondent data, or modify account settings.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82279] HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, all…
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82284] Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, D…
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82285] bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/…
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host filtering. Unauthenticated attackers can supply arbitrary URLs to enumerate internal network services and cloud metadata endpoints, then retrieve captured responses from object storage using ca…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82266] Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t…
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82268] Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsi…
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal addresses including metadata services and read retrieved content through parsed docum…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82270] Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/pr…
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lacks requestValidator middleware. Attackers can set the x-portkey-custom-host header to internal addresses and forward requests with Authorization headers to reach internal services and exfiltrate provider API keys.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75122] PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vul…
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-56100] SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows au…
SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55552] Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves …
Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configured staticRoots. A path containing traversal segments can escape the intended web root and return an arbitrary readable host file. The flaw is in yamcs-cor…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55484] ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking …
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the unchecked p[0] access without checking whether the resulting path is empty. An unauthenticated client can send a malformed…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55247] plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iC…
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar fil…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54745] Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. …
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de agotamiento de CPU en SvelteKit 2.49.0-2.52.1 permite denegación de servicio
SvelteKit versiones 2.49.0 a 2.52.1 con funciones remotas experimentales habilitadas contienen una vulnerabilidad que permite a atacantes enviar datos de formulario malformados para agotar recursos de CPU del servidor, causando indisponibilidad del servicio. Afecta aplicaciones web en producción en LATAM que usan estas versiones. La vulnerabilidad fue corregida en versión 2.52.2.