Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Perl" — 488 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89413] The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to,…
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-93436] vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests …
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92925] A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, P…
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92793] GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowi…
GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92763] Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters…
Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92761] WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only …
WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate that only checks grant existence.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-81563] A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS Servic…
A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.1…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-90042] In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filename…
In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffers The fscrypt subsystem uses the scatterlist crypto API, inheriting its requirement that any buffers are in the linear mapping region. However, the messenger client uses kvmalloc() to create buffers for messages, which will occasionally place those buffers in the vmalloc() regi…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89782] In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table …
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MAX entries During $LogFile replay, log_replay() indexes the transaction table by the transact_id taken from the log record header. check_log_rec() only verifies that transact_id is non-zero and properly aligned, not its magnitude, so a crafted image can request an arbitrarily la…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89774] In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properl…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready sk deref in sco_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk and parent sk is currently accessed without either, and without checking parent->sk_state: [Task 1] [Task 2] sco_so…
M Alto vulnerabilidad
16/09/2026
XikeStor Layer3: Falla de autenticación en descarga de configuración (CVE-2026-88263)
Los switches Layer3 de XikeStor carecen de validación de autenticación en el servicio de descarga de datos de configuración, permitiendo a atacantes no autenticados recuperar credenciales y configuraciones de red. Esta exposición es alta en entornos corporativos de LATAM que utilizan estos equipos como infraestructura core, riesgando acceso lateral a sistemas internos y uso como puente de salto hacia redes segmentadas.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27546] An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function…
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-14349] The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to auth…
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which …
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-73807] The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functi…
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76685] A vulnerability exists in the proxy packet processing logic of the affected component where it impro…
A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malformed or truncated input. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input that triggers an integer overflow. Successful exploitation could result in a buffer overflow, potentially leading to remote code execution or denial-…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76689] A vulnerability exists in the configuration processing logic of the affected component where malform…
A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow, potentially leading to remote code execution wi…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91985] Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share …
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19515] The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input …
The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit test execution flow. Successful exploitation of this vulnerability could lead to the execution of arbitrary OS commands o…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91751] Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entrie…
Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the project entries directory and manipulate arbitrary files and directories on the filesystem.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90942] Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /…
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global administrators.