Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54632] SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPack…
SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index untrusted bytes without sufficient length checks, while UdpReceiver.EndReceiveFrom closes the channel when those operations raise a non-socket exception. A remote party can s…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54182] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which i…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-55072] Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each value. When a data object of that class containing a Block field is loaded, Block::load in models/D…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57130] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/prais…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended criterion and alter IMAP operations when search_emails, reply_email, or archive_e…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-59569] An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allow…
An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-59570] On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler…
On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82441] Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `depend…
Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on the submission path, yet acts on them in two places. During cleanup of a finished topology, Nimbus deletes the keys named in those lists, and the deletion is perfo…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-54694] SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code fl…
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that str…
M Alto vulnerabilidad
09/09/2026
[CVE-2023-54393] PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON p…
PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-12855] Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in th…
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87553] Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote …
Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87510] Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attack…
Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75991] Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary…
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75999] ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary …
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must ope…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-58941] In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input…
In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-55273] In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improp…
In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78518] Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a …
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73021] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-72994] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-72996] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.