Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2270 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1799
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-18265] OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al…
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access t…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-18264] NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows r…
NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4000 by default. The issue results from the lack of proper validation of a user-supp…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-15679] Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution…
Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-15686] Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. Th…
Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multi_query method. The issue results from an incorrect check of a function return value. An attacke…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-75140] jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnera…
jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers ca…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-19611] A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode …
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-61897] An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges …
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
Control de acceso roto sin autenticación en Koji versiones <= 2.2.1
Se ha identificado una vulnerabilidad de control de acceso quebrantado en Koji
M Crítico vulnerabilidad
Hace 4 días
Inyección SQL sin autenticación en Directory Pro <= 2.5.8
Se ha identificado una vulnerabilidad crítica de inyección SQL sin autenticación en Directory Pro versión 2.5.8 y anteriores (CVSS 9.3), que permite a atacantes ejecutar comandos SQL arbitrarios contra bases de datos expuestas. Esta vulnerabilidad afecta directamente a empresas en México y Latinoamérica que utilicen este software para gestionar directorios corporativos, comprometiendo la confidencialidad e integridad de datos sensibles. El riesgo es crítico dado que no requiere credenciales para su explotación.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-66614] Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-13097] A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri…
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized a…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-15049] The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a …
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76764] A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an un…
A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76357] In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a craf…
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role for the request and does not restrict the user-supplied file path to the intended temporary directory. For more information…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76338] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who …
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service availability. The vulnerability is possible because the distributed search authentication token endpoint does not require a signe…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76321] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user coul…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could inject arbitrary Search Processing Language (SPL) into requests that search for events near a selected event. This could allow for unauthorized search execution. The vulnerability is possible because Splunk Web does not consistently escape caller-supplied values when it builds SPL for nearby-event…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76325] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power"…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds the "power" Splunk role could store a malicious ui-tour knowledge object that matches an auto-tour page name and share the object at the app level. The object can execute arbitrary JavaScript in the browser of another authenticated user who visits a standard Splunk Web page. The JavaScript could expose all rel…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76262] In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus servi…
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76139] A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a s…
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to u…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-75569] A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remot…
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to t…