Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ui" — 870 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19885] OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. T…
OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing o…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19886] OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This…
OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of O…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-19773] libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerabili…
libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of HTTP/2 HPACK path header. The issue results from the lack of proper valid…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19781] Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability.…
Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81235] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vul…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81236] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81238] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Cri…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81239] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81240] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-59160] Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-gra…
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55692] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON returned through includes/EmbedService/AbstractEmbedService.php into the data-mw-i…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-53710] MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to …
MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal dangerous dunder strings. An attacker can construct dun…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19780] Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac…
Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 8081 by default. The issue results from the lack of proper validation of a user-supplied string befo…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-54077] ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/ja…
ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java without validation. An authenticated user with SQL command access through /api/v1/command …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57586] CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior t…
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and p…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-55158] Conflibot warns in advance when merging a pull request will cause conflicts in other open pull reque…
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55178] GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map …
GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a second caller-influenced dataset reached through a relationship, map layer, VRT source, externalId lookup, or request body. When a public map references a private…
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica de bypass de autorización en Casdoor 4.4.0 y anteriores
Casdoor versiones hasta 4.4.0 presenta una vulnerabilidad de bypass de autorización en el endpoint /api/mcp que permite a atacantes con credenciales válidas (clientId y clientSecret) de cualquier aplicación acceder sin restricciones a la administración de usuarios en todas las organizaciones. Los atacantes pueden enumerar registros de usuarios incluyendo salts de contraseñas y direcciones de correo, crear cuentas administrativas, modificar y eliminar usuarios existentes. Este riesgo es crítico para empresas en LATAM que utilizan Casdoor en entornos de producción con múltiples organizaciones o tenants.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica de autenticación en Pig anterior a 4.1.0 permite control administrativo
Pig versiones anteriores a 4.1.0 presentan una vulnerabilidad de omisión de autenticación en el endpoint /register/password que descarta la verificación de contraseña actual, permitiendo a atacantes remotos reescribir credenciales de cualquier cuenta incluyendo administrador con CVSS 9.1. Esta falla expone sistemas de gestión de identidades en empresas LATAM a toma de control administrativo completo sin credenciales válidas.
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad SSRF alta en KubeSphere hasta v4.1.3 permite exfiltración de credenciales
KubeSphere versiones hasta 4.1.3 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en el endpoint de verificación de credenciales Git que acepta URLs sin validación. Atacantes autenticados pueden acceder a servicios internos y extraer credenciales básicas almacenadas en Secrets de cualquier namespace explotando el manejo de errores del endpoint. Este riesgo es alta para plataformas Kubernetes en producción en LATAM que usen KubeSphere como orquestador de contenedores.