Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1805
Esta semana
RSS
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad alta de SSRF en Serendipity anterior a 2.6.0 permite bypass de filtros
Serendipity antes de la versión 2.6.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) que permite a usuarios autenticados con permisos de adminImagesAdd eludir validaciones mediante direcciones IPv4 hexadecimales, literales IPv6 y rangos link-local. Los atacantes pueden acceder a servicios internos y extraer cuerpos de respuesta a través del módulo de cargas públicas, exponiendo datos sensibles de infraestructura interna en empresas con Serendipity expuesto en Internet.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18952] Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics…
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-65941] In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network a…
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73264] Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provide…
Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST /api/v1/lighthouse/providers/{id}/connection, causing api/src/backend/tasks/jobs/lighthouse_providers.py to send outbound requests, including the API key …
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16294] The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of…
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73247] Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/mai…
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that ac…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70324] Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70326] Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58612] Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to d…
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73080] SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/s…
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and no target validation, allowing anyone who can reach a volume server's gRPC port to cause requests to…
M Alto vulnerabilidad
11/08/2026
Vulnerabilidad alta de SSRF en Pinry 2.1.13 permite ataques sin autenticación
Pinry versión 2.1.13 y anteriores contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) que permite a atacantes no autenticados forzar al servidor a realizar solicitudes HTTP a hosts internos o externos arbitrarios mediante la función de importar pines por URL. La vulnerabilidad existe porque la URL proporcionada por el usuario se pasa directamente a requests.get() sin validación de host o IP, y el registro de nuevos usuarios está habilitado por defecto, permitiendo activación anónima del exploit. Esto afecta principalmente a plataformas de gestión de contenido visual en entornos empresariales y educativos de LATAM.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72552] A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote at…
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from clou…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-50236] An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supp…
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-50237] A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog …
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19516] A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re…
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad SSRF alta en Koito v0.3.2 permite ejecución de requests arbitrarios
Se ha identificado una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en Koito versiones hasta v0.3.2 que permite a usuarios autenticados forzar al servidor a realizar peticiones HTTP hacia hosts internos o externos mediante parámetros malformados en el endpoint PATCH /apis/web/v1/album/{id}/image. Esta vulnerabilidad (CVSS 7.7) compromete la integridad de la red interna y puede facilitar acceso no autorizado a servicios internos, representando un riesgo significativo para infraestructuras en LATAM que utilicen este software.
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad SSRF alta en xiaoai-patch permite solicitudes HTTP no autorizadas
Una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en xiaoai-patch (commit fb07049) permite a atacantes remotos forzar altavoces inteligentes Xiaomi a realizar peticiones HTTP hacia URLs internas o externas arbitrarias. El endpoint /auth en api/main.py no valida el parámetro url en solicitudes POST, exponiendo redes internas y servicios Home Assistant en organizaciones de México y Latinoamérica que utilicen este parche.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72566] A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a lo…
A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app's Custom Request action.
M Alto vulnerabilidad
09/08/2026
[CVE-2026-19374] A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593a…
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maint…
M Alto vulnerabilidad
08/08/2026
[CVE-2026-67620] Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard impleme…
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force the server to issue arbitrary GET requests to cloud instance metadata services. …