Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad SSRF alta en Foxit PDF Services API permite acceso a archivos internos
La API de Foxit PDF Services contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) con puntuación CVSS 8.5 que permite a atacantes eludir validaciones mediante redirecciones URL y acceder a archivos locales y recursos internos. Empresas en México y LATAM que utilizan esta API para procesamiento de documentos PDF en aplicaciones web enfrentan riesgo de exposición de información sensible, credenciales y datos de configuración de servidores.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16268] The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing r…
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de SSRF en JeecgBoot hasta versión 3.9.2
Se identificó una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en JeecgBoot versiones hasta 3.9.2, específicamente en el componente Anonymous Chat Attachment Parser (/airag/chat/send). El defecto permite a atacantes remotos ejecutar solicitudes HTTP arbitrarias desde el servidor afectado, comprometiendo sistemas internos y datos sensibles. La vulnerabilidad tiene código de explotación público disponible, aumentando significativamente el riesgo para empresas LATAM que usan esta plataforma en producción.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18973] A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is …
A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early …
M Alto vulnerabilidad
05/08/2026
[CVE-2026-34966] Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated…
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arbitrary URLs through release asset download URLs, pull-request patch URLs, or OAuth avatar endpoints …
M Alto vulnerabilidad
05/08/2026
[CVE-2026-55524] PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs it…
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal destinations. The check resolves the hostname once with socket.gethostbyname and rejects private/loopback/link-local results, but then passes the URL to a fetcher …
M Alto vulnerabilidad
05/08/2026
[CVE-2026-9081] IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forge…
IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation, scheme/host allowlisting, or filtering of private IP ranges (loopback, RFC1918, l…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-17617] IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SS…
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-9203] A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 al…
A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71280] go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL us…
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback(), IsPrivate(), IsUnspecified(), or IsLinkLocalUnicast() checks). An authenticated user creating or updating a bookmark via POST /api/bookmark, PUT /api/v1/bookmarks/cache, or POST /api/bookmarks/ext can s…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71270] Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with…
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf). The endpoint validates only that the initial requested URL resolves to a public IP, then fetches the page's HTML server-side and hands it, unsanit…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71271] Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP …
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified() — unlike the correctly implemented sibling function isInternalIP() in internal/httpgetter/html_meta.go, which does. Because Linux redirects connections to 0.0.0.0 to loopback (127.0.0.1), an attacker registering a w…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71211] MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/ser…
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full re…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-70485] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the literal IPv6 address without examining IPv4 addresses embedded in transition encodings. On a deployment with a NAT64 gateway, any verified user could wrap an internal or…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-70479] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource requests pass unvalidated. A page supplied by an authenticated user can use JavaScript to reach blocked internal addresses, and returned DOM can include data read f…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47616] NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker m…
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47617] NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker m…
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47618] NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attac…
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47613] NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of …
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-47614] NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request for…
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.