Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 918 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
Falta de autenticación en Progress Fiddler Everywhere 8.0.2 permite acceso no autorizado a tokens OAuth
Progress Software Fiddler Everywhere 8.0.2 presenta una vulnerabilidad alta (CVSS 7.7) que permite a un atacante local sin credenciales acceder al backend .NET (Fiddler.WebUi) a través de canales HTTP y SignalR no autenticados. Esto posibilita la generación de tokens OAuth fraudulentos y la lectura del certificado raíz man-in-the-middle. Afecta principalmente a desarrolladores y equipos de testing que utilizan esta herramienta en México y Latinoamérica para análisis de tráfico HTTPS.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-16513] The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/…
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user m…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101916] @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. P…
@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer certificates when server credentials set requireClientCertificate to false. When applications use the returned authentication context, they can treat an unauthorized certificate as authorized, causing im…
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en NeuVector permite inyección de comandos OS en contenedores privilegiados
NeuVector versiones 5.4 (anteriores a 5.4.11) y 5.5 presenta manejo inadecuado de parámetros que permite a usuarios autenticados con permisos de escritura en Políticas Runtime o acceso a claves gRPC internas inyectar comandos del sistema operativo en contenedores enforcer privilegiados. Esto resulta en compromiso total del nodo worker. Afecta principalmente a infraestructuras containerizadas en Azure, AWS y datacenters locales de la región.
M Crítico vulnerabilidad
28/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en FAST FAC1200R 5.0
Se ha identificado un desbordamiento de búfer basado en pila (stack-based buffer overflow) en la función parse_advertisement_frame del servicio devdiscover del dispositivo FAST FAC1200R versión 5.0_20201119_1.0.2, con puntuación CVSS 9.9. La vulnerabilidad puede ser explotada remotamente sin autenticación, permitiendo ejecución de código arbitrario en routers empresariales y de pequeños negocios ampliamente desplegados en México y Latinoamérica. El exploit es público y el fabricante no ha respondido a solicitudes de parche.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82386] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog adminis…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator boo…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de deserialización insegura en MONAI anterior a v1.6.0
MONAI antes de la versión 1.6.0 contiene una vulnerabilidad de deserialización insegura en la clase NumpyReader que utiliza numpy.load con allow_pickle=True sin validación, permitiendo a atacantes ejecutar código arbitrario mediante archivos .npy y .npz maliciosos en pipelines de datos estándar. Esta vulnerabilidad afecta especialmente a organizaciones en LATAM que utilizan MONAI en aplicaciones de análisis médico, investigación biomédica e inteligencia artificial sin restricciones en el origen de los datos de entrenamiento.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en AzuraCast permite acceso a recursos de red restringidos
AzuraCast (versión anterior a 0.23.8) presenta una falla en la validación de URLs de retransmisión remota que permite a usuarios con permisos limitados apuntar a direcciones internas (loopback y redes privadas). Esta vulnerabilidad afecta principalmente a proveedores de streaming y radios en línea que operan la plataforma en entornos corporativos compartidos en México y Latinoamérica.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100720] Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowe…
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100708] Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key con…
Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are passed through ApiCommand::response() without any field stripping or allowlist. A low-privileged authenticated customer API calle…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100673] The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render s…
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor wh…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100663] Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not spe…
Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 in HttpConversionUtil.toHttp3Headers. The authority-form target (e.g., "CONNECT trusted.example:443") is parsed as a URI, so its host is emitted as :scheme, :path is set to "/", and the HTTP/1 Host head…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100665] Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix…
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can presen…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100622] capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from…
capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Slack 2026.8.0 y anteriores permite bypass de políticas de remitentes
OpenClaw Slack versiones anteriores a 2026.8.1 no validan correctamente las listas de remitentes autorizados en mensajes directos grupales, permitiendo a participantes no autorizados activar agentes de Slack y acceder a herramientas y datos. Esta falla de control de acceso afecta principalmente a organizaciones en LATAM que utilizan automatización de Slack para gestionar datos sensibles, cumplimiento normativo y comunicaciones altas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100551] OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the C…
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attacker able to redirect the same host and port and present a different certificate that is accepted by …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100541] OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 low…
OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a c…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-57443] SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 an…
SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configur…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-91838] A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivilege…
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then processed by the `pppd` daemon, which runs with root privileges, allowing the attacke…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-91839] A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fo…
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject additional configuration directives. This can lead to arbitrary code execution with root p…