Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-12940] IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via e…
IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS blocklist fails to include SHELLOPTS , BASHOPTS , and PS4 environment variables.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-52680] Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when …
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. Thi…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-4978] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-28323] SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This…
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-28812] UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attac…
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15435] IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a …
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-11707] IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affecte…
IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-59309] VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A ma…
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-59310] VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor …
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-47876] VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A m…
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-54363] CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthentic…
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all installations. Attackers can use the hardcoded key to craft valid x-glad-auth headers and call privileged API endpoints such as a…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44108] Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematur…
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-7849] Due to improper neutralization of special elements, an unauthenticated remote attacker is able to in…
Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44100] The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points.…
The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44101] Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker…
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44104] The firmware update process for the basemodule of the charging controller only validates the CRC32 c…
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44092] An unauthenticated remote attacker can inject malicious input into the ModbusServer application beca…
An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44090] Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which …
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44091] An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creatio…
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-58046] Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user t…
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.