Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 10 min
Buscando: "Quest" — 2124 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72798] SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeVie…
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block ty…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19228] GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 …
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13267] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-12004] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by crafting a malicious HTTP request.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-12005] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-12359] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18952] Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics…
Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19311] Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an…
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-48551] Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protect…
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73292] Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/pas…
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in ve…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73291] Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to v…
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId route, allowing a malicious or compromised Jellyfin or Emby server, or a man-in-the-middle attacker…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73286] RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_cond…
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated callers to satisfy identity-based policy conditions. This issue is fixed in version 1…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73264] Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provide…
Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST /api/v1/lighthouse/providers/{id}/connection, causing api/src/backend/tasks/jobs/lighthouse_providers.py to send outbound requests, including the API key …
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16294] The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of…
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks that can target internal services.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-16051] The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages inst…
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad alta en Red Hat Advanced Cluster Management permite acceso no autorizado a secretos
Una flaw en el componente multicloud-operators-channel de Red Hat Advanced Cluster Management (RHACM) permite que agentes comprometidos de clústeres gestionados accedan sin autorización a Secrets y ConfigMaps en namespaces de Channel, exponiendo credenciales de Git, Helm y otros servicios de múltiples tenants. El impacto es alta en entornos multicloud híbridos comunes en empresas de LATAM que utilizan RHACM para orquestar infraestructura en AWS, Azure y plataformas on-premise.
F Medio vulnerabilidad
12/08/2026
Server-Side Request Forgery (SSRF)
Fortinet PSIRT publica advisory de seguridad: Server-Side Request Forgery (SSRF). Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortisiem.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-66147] An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in G…
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63177] Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access contro…
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../upload/...`) so that Nginx routes the request to a …
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73032] PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to e…
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt injection in PDFs, MITM interception of API requests, or a malicious custom LLM endpoint to execute arbitrary code in Zotero…