Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 50 min
Buscando: "Nsa" — 141 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-70410] Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in …
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary classes via unrestricted calls to Class.forName(String) which by default triggers initialization. This may lead to the execution of static initializer blocks in arbitrary classes…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65178] NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted mod…
NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de ejecución remota de código en openEQUELLA anterior a versión 2026.1.0
openEQUELLA versiones anteriores a 2026.1.0 contienen una vulnerabilidad de ejecución remota de código (RCE) en la compilación de plantillas FreeMarker debido a una configuración insegura de TemplateClassResolver. Atacantes autenticados pueden inyectar expresiones maliciosas a través de resúmenes de colecciones, portlets de panel o plantillas MIME para instanciar clases peligrosas como freemarker.template.utility.Execute e invocar comandos del sistema operativo. Esta vulnerabilidad afecta principalmente a instituciones educativas y de investigación en LATAM que utilizan openEQUELLA como repositorio digital.
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94084] Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by r…
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63452] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli compression bombs a single flow can submit. With response-body-decompress-layer-limit enabled, repeated compressed responses make the decompression paths in …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63446] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transact…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63447] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-57227] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or d…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93762] Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An app…
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93765] Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-docum…
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result in unintended removal of stored records and in the embedding application becomin…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11375] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
M Alto vulnerabilidad
18/09/2026
[CVE-2025-61682] Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query dat…
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en Netty: fuga de memoria en StompSubframeDecoder (CVE-2026-93494)
Se identificó un fallo en el componente StompSubframeDecoder de Netty que permite a atacantes remotos provocar una fuga permanente de memoria mediante frames STOMP malformados sin byte nulo de terminación. La acumulación descontrolada de memoria puede derivar en Denegación de Servicio (DoS), afectando aplicaciones que utilizan este framework para procesamiento de mensajes en tiempo real, especialmente en plataformas de comercio electrónico, sistemas financieros y comunicaciones altas en la región.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-67103] HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could a…
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92934] vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape…
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to access unsanitized host proxies embedded in the errors array, enabling full remote code execution and process information dis…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92903] Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-control…
Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a malicious project configuration file or craft command-line input can cause Snowflake CLI to execute attacker-controlled SQL statements in the context of the victim's Snowf…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66269] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Contr…
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92838] A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The appli…
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92593] Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controll…
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on …
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-75513] Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9…
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a dictionary indexer key used by Where filters in src/Marten/Linq/Members/Dictiona…