Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Rti" — 221 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91812] A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to …
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-82843] The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID …
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-89425] UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token t…
UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three sibling parser implementations, including UTF8StreamJsonParser, it never consults ErrorReportConfiguration.getMaxErrorTokenLength() (default 256). A malformed toke…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-61685] ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list …
ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing unauthenticated attackers to inject SQL through crafted query string keys. Version 3.7.0…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-88419] An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m…
An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execute arbitrary PHP code on the server, because the stored file extension is taken verbatim from the client-supplied filename with no extension allowlist or content va…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95831] Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Pyth…
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be inv…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-57149] plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as …
plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-85995] Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ update…
Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its Authenticode digest is invalid. An attacker who can replace or plant the updater-related file can cause Notepad++ to launch attacker-modified code when a user trig…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-84388] A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Ext…
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65118] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause im…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de escalada de privilegios en CUPS y cups-filters
Se identificó una vulnerabilidad de escalada de privilegios (CVSS 8.2) en CUPS cuando se utiliza con el backend serial de cups-filters. Un usuario local miembro del grupo lpadmin puede configurar una impresora con backend serial privilegiado para escribir datos arbitrarios en cualquier archivo del sistema con permisos de root. Esta falla afecta especialmente a infraestructuras de impresión compartida en empresas medianas y grandes en México y Latinoamérica.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-74766] Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decod…
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the insertion pointer first and only then grows the buffer when the code point does not fit. The growth reall…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-87079] Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost …
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertion point by scanning that buffer from the start, one character at a time. The scan runs once per code point over the output built so far, so the cost is quadratic i…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94623] vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix cachin…
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of va…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-55897] luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to r…
luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in applications/luci-app-advanced-reboot/root/usr/share/rpcd/acl.d/luci-app-advanced-reboot.json grants rpcd file.exec permission f…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/09/2026
[CVE-2026-49810] Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive …
Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94184] A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious …
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure …
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-94301] The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypa…
The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed a…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-91864] A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which N…
A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-85017] The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability ch…
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable ac…