Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47623] NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of un…
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-69098] kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection e…
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with appli…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18642] Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Ins…
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4.
M Alto vulnerabilidad
03/08/2026
Vulnerabilidad alta de deserialización en PRISMAproduction 6.5 y anteriores permite ejecución remota de código
Una vulnerabilidad de deserialización en PRISMAproduction versión 6.5 o inferior permite a atacantes ejecutar código arbitrario en sistemas afectados. Con puntuación CVSS 7.5, esta falla representa un riesgo significativo para infraestructuras empresariales en México y Latinoamérica que implementen esta solución en entornos de producción. La explotación no requiere interacción del usuario y puede comprometer la integridad y confidencialidad de datos altas.
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-68771] ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node tha…
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt ref…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-12720] The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when i…
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the stored data. With a suitable gadget chain present on the site (via another installed Kirki WordPress plugin before 6.0.13, , or an outdated WordPress v…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-11536] IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability i…
IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15969] SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickle…
SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15976] SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace reposit…
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-12118] IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to …
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-57859] e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization h…
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The e_array::unserialize() function in e107_handlers/core_functions.php performs only a prefix check for the string 'array' before passing the st…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-1360] The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versio…
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-58163] Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or cras…
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14974] IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute a…
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
M Crítico vulnerabilidad
28/07/2026
[CVE-2026-14512] IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe…
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/07/2026
[CVE-2026-66713] Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache So…
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered …
M Crítico vulnerabilidad
28/07/2026
[CVE-2026-11756] A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE pla…
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
J Alto vulnerabilidad
27/07/2026
[CVE-2026-65617] A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user t…
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-63077] In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible …
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
M Alto vulnerabilidad
26/07/2026
[CVE-2026-15962] The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all v…
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over a…