Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 2131 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-75887] A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal …
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-19125] The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all version…
The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executi…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96556] A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function …
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not res…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-6935] IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executabl…
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96889] A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincl…
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94183] Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page…
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84714] A flaw was found in the automation-controller input-validation guard sanitize_jinj…
A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accep…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-84719] A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplat…
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permiss…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84691] A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that f…
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that w…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-75884] A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist th…
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96541] A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can o…
A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is clos…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95515] Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94174] Administrator SQL Injection in Email Log <= 2.63 versions.
Administrator SQL Injection in Email Log
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84499] A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions o…
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and includes its plaintext value in the minimum/maximum len…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-84474] A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-c…
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback endpoint trusts a client-supplied X-Forwarded-For header to determine the calling ho…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-77602] OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or mor…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution privilege tier. Table and command or telemetry definitions are processed through Config…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-77394] OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or mor…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /openc3-api/screen whose BUTTON widget action is evaluated by openc3-cosmos-init/plugins/packages/openc3-vue-common/src/widgets/ButtonWidget.vue in another operator's …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76087] Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous form…
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete submission without session binding, ownership validation, or a valid submissionEditToken. An unauthenticated attacker can enumerate sequential IDs and overwrite or hij…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-61814] Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work wh…
Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remote attacker who controls untrusted JSON input and its chunk sizes can exhaust CPU resources and cause denial of service in applications using AsyncParser. This iss…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-96759] orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanSta…
orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated hooks are called.