Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 173 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66465] Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28189] Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
Unauthenticated Arbitrary File Deletion in Participants Database
M Alto vulnerabilidad
13/08/2026
[CVE-2026-48702] Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.…
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed size. The existing `max_apk_metadata_size` check (default 1MB) is only applied to individual tar entr…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-49478] Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC)…
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts.…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-66898] A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during back…
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing pa…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13105] IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal expl…
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-14866] IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certifica…
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-63293] A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write op…
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this flaw by providing a crafted image archive with a symlinked metadata.yaml file pointing to target file paths on the host sys…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19311] Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an…
Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73299] Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the T…
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-69106] A low-privileged user may poison cached artifact metadata under specific conditions, potentially cau…
A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-42018] JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when an…
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-69105] An unauthenticated attacker may cause untrusted package content to be cached under specific conditio…
An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.
M Alto vulnerabilidad
12/08/2026
[CVE-2025-59319] CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intende…
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-70468] A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.…
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-26035] An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through …
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
M Alto vulnerabilidad
12/08/2026
Desbordamiento de búfer alta en Fortinet FortiClient Windows permite ejecución remota de código
Una vulnerabilidad de desbordamiento de búfer en Fortinet FortiClient Windows (versiones 7.2.0-7.2.11 y 7.4.0-7.4.3) permite a atacantes no autenticados ejecutar código arbitrario manipulando respuestas DNS. El ataque requiere posición en la red para alterar tráfico DNS, afectando principalmente a empresas en LATAM con VPN corporativos que confían en FortiClient para acceso remoto seguro.
P Medio vulnerabilidad
12/08/2026
CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Palo Alto Networks PSIRT publica advisory de seguridad: CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability (Severity: MEDIUM). Tipo: Vulnerabilidad de seguridad. Producto afectado: GlobalProtect.
M Alto vulnerabilidad
12/08/2026
CVE-2026-66878: Vulnerabilidad de divulgación de información en multicloud-operators-subscription
Se ha identificado una falla en multicloud-operators-subscription que permite a administradores de namespace con privilegios acceder a secretos almacenados en otros espacios de nombres mediante manipulación del campo Channel.Spec.SecretRef.Namespace. Esta vulnerabilidad (CVSS 7.7) expone credenciales, tokens API y datos sensibles en entornos multicloud comúnmente utilizados en infraestructuras híbridas de empresas latinoamericanas. El riesgo se amplifica en organizaciones con múltiples equipos compartiendo clusters Kubernetes.
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad alta en UEFI por falta de verificación de arranque seguro
Una vulnerabilidad en firmware UEFI (CVE-2026-6484, CVSS 8.2) permite la ejecución arbitraria de código debido a la ausencia de verificación criptográfica en ciertos módulos de firmware (FV). Esta falla compromete la cadena de confianza de arranque en servidores, estaciones de trabajo y dispositivos empresariales, siendo particularmente alta en infraestructuras cloud y centros de datos en LATAM donde el firmware no parchado es común.