Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,201
Total alertas
3242
Críticas
10686
Altas
8
Ransomware
963
Esta semana
RSS
J Crítico vulnerabilidad
10/07/2026
[CVE-2026-59792] In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project wor…
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59793] In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integr…
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59794] In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-re…
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59795] In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
J Alto vulnerabilidad
10/07/2026
[CVE-2026-59796] In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission …
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-56765] Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes s…
Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task IDs but fetches attachments by sequential ID without verifying ownership, allowing attackers to download and delete all fi…
K Alto vulnerabilidad
10/07/2026
[CVE-2026-56261] Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API …
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal se…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/07/2026
[CVE-2026-56279] Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RP…
Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users' organization membership, roles, management emails, and billing metadata.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-56305] Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoin…
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-56254] In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distrib…
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by …
M Alto vulnerabilidad
10/07/2026
[CVE-2026-29519] Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflect…
Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path parsing that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser by embedding HTML or JavaScript payloads within the request path. Attackers can craft a malicious URL containing injected script content that i…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-38057] The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication…
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate devi…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-38059] The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An …
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, …
M Alto vulnerabilidad
10/07/2026
[CVE-2026-22659] FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that …
FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in forums they do not control by submitting crafted topic ID lists. Attackers can include a low-ID topic from a permitted forum as an anchor in a batch request, causing the permission check applied only to the first result to …
M Alto vulnerabilidad
10/07/2026
[CVE-2026-22660] FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows auth…
FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. The bulk AJAX endpoint in the management views compares received JSON integer group IDs against string literals, causing the protection check to always pass, which …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
D Alto vulnerabilidad
10/07/2026
[CVE-2026-54469] Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untruste…
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
D Crítico vulnerabilidad
10/07/2026
[CVE-2026-56688] Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special E…
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and latera…
D Alto vulnerabilidad
10/07/2026
[CVE-2026-56689] Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special E…
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
D Alto vulnerabilidad
10/07/2026
[CVE-2026-56690] Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special E…
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.
L Crítico vulnerabilidad
10/07/2026
[CVE-2026-53363] In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-fr…
In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is the same class of bug that was fixed in skb_try_coalesce() for CVE-2026-46300: when fragments backed by read-only page-cach…