Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-15815] Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin arch…
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote cod…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-47252] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INS…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a SQL-controlled URL into AppleScript or JXA source passed to osascript. In plugins/chrome/tabs.go, tabsTable.Insert() pas…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92937] vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js pr…
vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a rejected host Promise value. Registering the rejection handler through Function.prototype.call or .apply indirection (e.…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-62104] Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
Unauthenticated Remote Code Execution (RCE) in Migratico Lite
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86320] A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources wit…
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-88795] The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authenticat…
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92593] Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controll…
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92784] @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into gen…
@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-73456] Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampli…
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63325] Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version …
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92125] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTrans…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and executing arbitrary code in the context of the Jenkins controller JVM.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92127] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpat…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
M Crítico vulnerabilidad
16/09/2026
Vulnerabilidad crítica en Arista EOS con P4Runtime permite ejecución remota de código
Una vulnerabilidad de puntuación CVSS 10 en Arista EOS permite que clientes no autenticados ejecuten código arbitrario con privilegios administrativos en switches configurados con P4Runtime. Aunque P4Runtime está deshabilitado por defecto, equipos que lo han activado para programabilidad de red enfrentan riesgo crítico. Esta falla afecta especialmente a proveedores de servicios y operadores de centros de datos en Latinoamérica que utilizan infraestructura Arista.
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS permite ejecución remota de código con privilegios root
Arista EOS presenta una vulnerabilidad (CVSS 8.8) en la interfaz gRPC Network Management Interface (gNMI) que permite a clientes autenticados ejecutar código arbitrario con privilegios root en switches de red. Afecta infraestructuras altas de centros de datos y proveedores de servicios en LATAM que utilizan equipos Arista con gNMI habilitado. El riesgo es elevado en entornos de nube privada y redes corporativas donde estos switches gestionan tráfico sensible.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-53710] MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to …
MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, and relies on validate_code checks for literal dangerous dunder strings. An attacker can construct dun…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
Ejecución de código arbitrario en PraisonAI anterior a 1.7.2 (CVE-2026-57141)
PraisonAI, plataforma de orquestación de agentes IA, contiene una vulnerabilidad crítica (CVSS 9.8) en la herramienta codeMode que permite ejecución de código JavaScript arbitrario. Un atacante puede eludir el blocklist de expresiones regulares mediante Function('return this')() y acceder dinámicamente al módulo child_process, logrando control total del servidor. Afecta versiones previas a 1.7.2 y compromete sistemas que ejecuten agentes IA en producción en LATAM.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-62379] Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentic…
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without verifying that it implements DSAMECallbackInterface. Default configurations expose the endpoint without authentication, allowing…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-16428] IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacke…
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57131] PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts pr…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool c…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90553] vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor l…
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.