Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 2132 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-96755] orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect gen…
orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96513] A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown p…
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, a…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96514] A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the…
A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a rolling release to provide …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93349] Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console…
Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-88830] A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication h…
A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-85724] Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are config…
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either identity can broaden the substituted filter and gain cross-tenant read and write acce…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-6668] Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthentic…
Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the proc…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96673] Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that all…
Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-19179] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipu…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-18875] IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unau…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payme…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96275] A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary loc…
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-96276] If a malicious SDK container declares an extension point with a crafted `directory` path, and a deve…
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86679] ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permission…
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86681] ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permission…
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86677] ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user t…
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86678] ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user t…
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-59167] SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. P…
SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler attributes to remain on crafted elements. When an application renders attacker-controlled editor content and a user interacts with the element, the retained handl…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-86246] Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled …
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are r…
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad de Control de Acceso en ManageEngine OpManager y Firewall Analyzer (CVE-2026-84791)
ManageEngine OpManager y Firewall Analyzer versiones 12.8.710 e inferiores contienen una vulnerabilidad de control de acceso deficiente (CVSS 7.1) que permite a usuarios autenticados con privilegios bajos modificar configuraciones de reportes de Change Management en firewalls fuera de su alcance asignado. Esto afecta directamente a empresas en México y LATAM que utilizan estas soluciones para gestión de infraestructura de red y firewall. El riesgo se incrementa en organizaciones con múltiples equipos de operaciones sin segmentación adecuada de permisos.
M Alto vulnerabilidad
23/09/2026
Escalada de privilegios alta en ManageEngine OpManager y Firewall Analyzer v12.8.710
ZohoCorp ManageEngine OpManager y Firewall Analyzer versiones 12.8.710 y anteriores contienen una vulnerabilidad de escalada de privilegios (CVSS 8.1) que permite a usuarios autenticados con permisos bajos obtener acceso administrativo mediante la importación maliciosa de perfiles de reportes. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan estas herramientas para monitoreo de infraestructura y gestión de firewall.