Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3515 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1261
Esta semana
RSS
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Submariner: inyección de configuración en modo cert-auth
Se identificó una falla en Submariner que permite inyección de configuración arbitraria en modo autenticación por certificados. Un cluster malicioso puede explotar esta vulnerabilidad publicando un CableName con saltos de línea y directivas de ipsec.conf sin validación previa, comprometiendo la seguridad de redes híbridas y multi-cluster. El impacto afecta directamente a empresas en LATAM con infraestructuras Kubernetes distribuidas en cloud público y privado.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Joro framework: exposición de API local sin autenticación
Joro, un framework de pruebas web, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.1 que expone una API local sin autenticación en 127.0.0.1:9090 con política CORS permisiva. Un atacante puede ejecutar JavaScript malicioso desde cualquier sitio visitado para cargar plugins nativos y comprometer completamente el sistema. Esta exposición afecta principalmente a equipos de seguridad y desarrolladores que utilizan Joro para análisis de aplicaciones web en infraestructuras empresariales de LATAM.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52831] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, ). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This iss…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52833] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-53635] Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commi…
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated user — including a learner account with zero course roles — can issue a single P…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84837] A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing th…
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with t…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84838] A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to e…
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84675] OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able…
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84670] Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can b…
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78689] Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list p…
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list cau…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78222] A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() c…
A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires control or influence over the fetched HTTP response. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system. There is no control plane exposure; th…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78410] A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pi…
A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-53611] Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary…
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in the input…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-66842] BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrat…
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. Th…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18058] The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired wit…
The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18329] Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access …
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition i…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78604] Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local p…
Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created with access controls broader than required. A local user could take advantage of this to cause the service to execute code o…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF en Simply Schedule Appointments <= 1.6.12.23 permite acciones no autorizadas
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) sin autenticación en Simply Schedule Appointments en versiones hasta 1.6.12.23. Esta vulnerabilidad permite a atacantes realizar acciones no autorizadas en nombre de usuarios legítimos, afectando principalmente a empresas de servicios, clínicas y consultorías en LATAM que utilizan este plugin para gestionar citas. Con un CVSS de 8.8, representa un riesgo alto para la integridad de datos y la continuidad operativa.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81769] Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation…
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19219] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog …
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.