Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 2134 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad de control de acceso en AzuraCast anterior a 0.23.8 expone credenciales de administración
AzuraCast versiones anteriores a 0.23.8 contiene un fallo de control de acceso en el endpoint GET /api/station/{id}/vue/profile que permite a usuarios autenticados con permisos limitados de visualización extraer contraseñas en texto plano de Icecast/Shoutcast (admin, origen y retransmisión). Usuarios con acceso de solo lectura pueden invocar este endpoint y recibir credenciales frontend en respuestas JSON, comprometiendo la seguridad de infraestructuras de streaming de radio y podcasting frecuentes en medios latinoamericanos.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad de inyección de comandos en AzuraCast 0.23.x afecta servidores de radio
AzuraCast versiones hasta 0.23.x contiene una vulnerabilidad de inyección de comandos en la generación de configuración de Liquidsoap para grabaciones en vivo. Usuarios autenticados con permisos de Streamers pueden insertar metacaracteres de shell en nombres de usuario y ejecutar comandos con privilegios del proceso Liquidsoap cuando finaliza la grabación. Esta vulnerabilidad afecta principalmente a emisoras de radio y plataformas de streaming que utilizan AzuraCast en infraestructura on-premise o en la nube en LATAM.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de deserialización insegura en MONAI anterior a v1.6.0
MONAI antes de la versión 1.6.0 contiene una vulnerabilidad de deserialización insegura en la clase NumpyReader que utiliza numpy.load con allow_pickle=True sin validación, permitiendo a atacantes ejecutar código arbitrario mediante archivos .npy y .npz maliciosos en pipelines de datos estándar. Esta vulnerabilidad afecta especialmente a organizaciones en LATAM que utilizan MONAI en aplicaciones de análisis médico, investigación biomédica e inteligencia artificial sin restricciones en el origen de los datos de entrenamiento.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de deserialización en MONAI anterior a 1.5.2 permite ejecución remota de código
MONAI versions anteriores a la 1.5.2 contiene una vulnerabilidad de deserialización de datos no confiables en la función algo_from_pickle que procesa archivos .pkl sin validación. Un atacante puede ejecutar código arbitrario mediante un archivo pickle manipulado si la aplicación lo procesa. Esta vulnerabilidad afecta directamente plataformas de análisis de imágenes médicas 3D en instituciones sanitarias y centros de investigación de LATAM.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100839] Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest ke…
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adve…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de ejecución remota de código en MONAI hasta versión 1.6.0
MONAI versiones 1.6.0 y anteriores contienen una vulnerabilidad de ejecución remota de código (RCE) en el motor de configuración de bundles que permite a atacantes ejecutar código arbitrario sin validación de lista permitida. Los agresores pueden distribuir bundles maliciosos con configuraciones manipuladas que se ejecutan cuando usuarios cargan bundles mediante monai.bundle.load(), afectando laboratorios de investigación médica y centros de datos en LATAM que implementan pipelines de procesamiento de imágenes médicas.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100744] A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function…
A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue.…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/09/2026
[CVE-2025-71426] Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering …
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator,…
M Alto vulnerabilidad
27/09/2026
[CVE-2025-71425] Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes …
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affected. This exposes workload secrets — normally accessible only to the Contrast Coordinator, the initi…
M Alto vulnerabilidad
27/09/2026
[CVE-2025-71423] Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.…
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user with get or list permission on pods/logs. Because workload secrets are used for encrypted storage and Vau…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100740] A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_param…
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100739] A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c…
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument seno results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for cont…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-72668] Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to p…
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation. A non-administrative user able to edit a shared agent could cause privileged operations to be carried out under the identity of a higher-privileged user who subsequently interacts with that agent. Where the same user can also author workflows, this can extend to full administrat…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-85984] The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to A…
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the mo_by_pass_login() function, which treats administrator role membership alone as suffici…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100720] Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowe…
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100713] Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH ke…
Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile() is done only at check time; the live filesystem path is re-resolved as root at write time (file_put_contents with FILE_APP…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100716] Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (…
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component…
M Crítico vulnerabilidad
26/09/2026
[CVE-2026-100717] froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl reje…
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or chan…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100718] Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.ad…
Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When an administrator has enabled the allowed-sender feature but disabled external allowed-sender domains (mail.enable_allow_sender = 1, mail.allow_external_domains = 0), an authenticated customer with API access can still use EmailSender.add to register an arbitrary external sender a…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100709] Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) wit…
Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and administrator IDs are allocated from separate namespaces, a remembered-2FA token legitimately issued to a customer with a given ID…