Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 2132 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-39353] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the directory is automatically trusted by Mdl_templates and can be selected as publi…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-42322] Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/…
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension, causing the file to be placed…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-42323] Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/…
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager filter URL without numeric validation. The URL filter parser stores those values in the bulk_manager_filter session state, and later query construction concatenates…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-42324] Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/…
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The stored album image_order expression is later concatenated into ORDER BY clauses by admin/batch_manager_global.php, admin/batch_manager_unit.php, include/section_init.in…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-33639] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter r…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84882] IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle …
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97865] A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Even…
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The patch is named 78c1222ec0e2119d84684032da1541120a2cdd23. The …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-93834] A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main…
A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path containing stale heap data, bypassing directory traversal restrictions and escaping the shared directory boundary. This can lead to arbitrary host file read/write and …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-85750] Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload…
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusion (e.g., disguising SVG content as PNG), an attacker can trigger unintended interpretation of embedded SVG elements that reference local files. In mor…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84884] IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible pla…
IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98112] In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix listener task lifeti…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix listener task lifetime on netdev events The listener thread exits when its listening socket is shutdown. The netdevice notifier shuts down the socket before calling kthread_stop(), so the task_struct can be freed before kthread_stop() gets its reference. Create the listener in a stopped state and hold an extra task_s…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98115] In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions du…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely drain sessions during logoff SMB3 multichannel allows requests for one session to run on multiple connections. Wait for all channels bound to a session before freeing shared session objects. A deferred byte-range lock remains counted as a running request and only wakes when its file closes. Wake blocked locks duri…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98108] In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan mode…
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan l2cap_new_connection() sets default value of channel mode to match the parent channel. l2cap_le_connect_req() left this at the default, and created L2CAP_MODE_EXT_FLOWCTL channels if listening pchan has that mode. This causes FLAG_DEFER_SETUP channels to reply…
C Informativo vulnerabilidad
25/09/2026
[CVE-2026-98084] In the Linux kernel, the following vulnerability has been resolved: bpf: backtracking shouldn't cle…
In the Linux kernel, the following vulnerability has been resolved: bpf: backtracking shouldn't clear outer frame R1-R5 for callbacks When processing calls to bpf_loop() verifier marks R1 (and R4) as precise. R1 tracks loop iterations number and because of the 'callback_depth < R1' mechanics in check_helper_call() must be marked precise. However, precision propagation for R1 was broken, when bpf…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98083] In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction use-afte…
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction use-after-free in raid stripe insertion If allocation of a RAID stripe extent fails, btrfs_insert_one_raid_extent() aborts and ends the transaction before returning -ENOMEM. btrfs_finish_one_ordered(), the production caller through btrfs_insert_raid_extent(), still owns the transaction handle. It handles …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98069] In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire the fastpath l…
In the Linux kernel, the following vulnerability has been resolved: net/rds: acquire the fastpath locks in rds_conn_shutdown() rds_conn_shutdown() quiesces the transmit and receive-refill paths by waiting for RDS_IN_XMIT and RDS_RECV_REFILL to be sampled clear, and then runs the transport shutdown and rds_conn_path_reset(). Sampling the bits clear is not the same as owning them: the moment afte…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98073] In the Linux kernel, the following vulnerability has been resolved: net: Remove conflicting altname…
In the Linux kernel, the following vulnerability has been resolved: net: Remove conflicting altnames for dying netns in __dev_change_net_namespace(). syzbot reported the warning in cfg80211_pernet_exit(). [0] The repro does the following: 1. create two device in root netns and non-root netns 2. assign the same altname for the two devices 3. remove the non-root netns Since commit 7663d52…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98050] In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_ptp: Fix napi_g…
In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context Currently mlxsw_sp1_ptp_ht_gc_collect() is run from the PTP garbage-collection workqueue, rather than the NAPI poll context. For any unmatched PTP entries carrying an SKB, it calls mlxsw_sp1_ptp_unmatched_finish() -> mlxsw_sp1_ptp_packet_finish(). For ing…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98030] In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: bound the CF…
In the Linux kernel, the following vulnerability has been resolved: net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size bcm_sf2_cfp_rule_get_all() walks the whole cfp.unique bitmap into rule_locs[] without consulting nfc->rule_cnt, which is how many entries the caller had room for. ETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN and the ioctl sizes the buffer from the rule_cnt …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-98017] In the Linux kernel, the following vulnerability has been resolved: net/sched: defer qdisc freeing …
In the Linux kernel, the following vulnerability has been resolved: net/sched: defer qdisc freeing after failed creation An RTM_NEWQDISC request can make clsact bind a populated shared ingress block during ->init(), publishing an embedded mini_Qdisc to lockless readers. If the same request has an invalid TCA_RATE, estimator setup fails after ->init(); the unwind removes the pointer but synchron…