Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-56449] Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response …
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-48005] Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server be…
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-14316] The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer…
The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted message. When sprintf() writes the full message, it can write past the end of the heap allocation.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12540] A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fet…
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ",…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12541] A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump …
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12544] A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/sett…
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code exec…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103921] GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.…
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12405] A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in th…
A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job T…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12423] A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable …
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-101888] The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability t…
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemChe…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-79896] Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parse…
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-46729] NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener…
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-47360] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod…
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97273] Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97277] Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
Subscriber Broken Access Control in Social Boost

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97284] Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
Contributor PHP Object Injection in Icegram
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97297] Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
Subscriber Broken Access Control in Gratisfaction
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97260] Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
Unauthenticated Cross Site Scripting (XSS) in MaxGalleria
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97268] Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce
M Alto vulnerabilidad
01/10/2026
[CVE-2026-94390] Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.
Editor PHP Object Injection in Hide Shipping Method For WooCommerce