Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 17 min
Buscando: "Ni" — 7308 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100889] A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the functi…
A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100886] A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. …
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100885] A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the…
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this is…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101065] Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, th…
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101084] obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allo…
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101062] Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=tr…
Obot before v0.23.0 (affected versions
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100875] A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d6…
A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Such manipulation of the argument myfid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. This product operates on a rolling relea…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100874] A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3…
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific ve…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101060] python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommuni…
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal services, allowing the UTCP client to reach cloud metadata endpoints or internal HTTP services and ret…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101044] pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.…
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101045] Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metada…
Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask metadata containing shell metacharacters (for example $(...) command substitution) could be carried into scripts that execute as root on managed macOS hos…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101043] pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable pla…
pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-destination key set that otherwise suppresses placeholder expansion for untrusted manifests (as alrea…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100870] Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-res…
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over …
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100871] Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identif…
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100872] Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, …
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/09/2026
Inyección Eval crítica en hMailServer 6.0.0-6.3.3 permite ejecución remota de código
Una vulnerabilidad crítica (CVSS 9.8) en el despachador de scripts JScript de hMailServer permite a atacantes no autenticados ejecutar código arbitrario con privilegios de servicio. La falla se activa mediante contraseñas manipuladas con secuencias de escape en autenticación SMTP, POP3 e IMAP. Afecta principalmente a servidores de correo en Windows en organizaciones de México y LATAM que usen versiones 6.0.0 a 6.3.3.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-96896] The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perfor…
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-86609] The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted throu…
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin befor…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en Coolify afecta autenticación de GitHub hasta versión 4.1.0
Se identificó una falla de autenticación en Coolify versiones hasta 4.1.0 en el manejador de configuración de GitHub App, permitiendo bypass de validación del parámetro 'state' en redireccionamientos. La vulnerabilidad es exploitable remotamente y su código de explotación está disponible públicamente. Empresas que usen Coolify como plataforma de despliegue o integración CI/CD deben evaluar inmediatamente su exposición.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de escape de sandbox en heym anterior a 0.0.91
heym versiones anteriores a 0.0.91 contienen una vulnerabilidad de escape de sandbox en el motor de expresiones que permite a usuarios autenticados ejecutar código Python arbitrario. Los atacantes pueden manipular expresiones de flujo de trabajo para acceder a funciones del sistema operativo y ejecutar comandos con los permisos del proceso backend, comprometiendo completamente servidores y sistemas de automatización en entornos empresariales.