Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 4276 resultados ✕ Limpiar búsqueda
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1755
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
[CVE-2026-3430] The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter befo…
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-43622] llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wr…
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger this memory management mismatch to cause denial of service through process crashes or potentially achieve arbitrary code …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18427] @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. …
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65541] Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Unauthenticated Broken Access Control in Staff Training
M Alto vulnerabilidad
06/08/2026
[CVE-2026-61964] Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16315] OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability …
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or un…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66733] Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in Receiv…
Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. The mUniquePacketID field is read directly from the UDP wire-format packet header without bounds checking, cau…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19036] A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C…
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-68481] In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully…
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2…
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de inyección de comandos en Shibby Tomato 1.28.0000
Se identificó una vulnerabilidad de inyección de comandos del sistema operativo en Shibby Tomato 1.28.0000 a través del parámetro new_qoslimit_enable en la función new_qoslimit_start del archivo /etc/qoslimit. Esta falla permite a atacantes remotos ejecutar comandos arbitrarios con privilegios del router, afectando principalmente a empresas y proveedores de servicios en LATAM que utilizan este firmware en equipos de red altas. El exploit está disponible públicamente.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-61466] In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and st…
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this…
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad XSS Almacenado alta en FormGent para WordPress (CVE-2025-15028)
El plugin FormGent para WordPress es vulnerable a inyección de scripts almacenados (XSS) en campos de formularios hasta la versión 1.9.2 debido a sanitización insuficiente. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta en navegadores de visitantes, comprometiendo datos de formularios y credenciales de clientes. Afecta directamente a pymes y emprendimientos en LATAM que utilizan este plugin para captura de leads, pagos y encuestas.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-54225] Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apa…
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size li…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-57817] The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter …
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-57819] Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFo…
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing  requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default li…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-64958] An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service …
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-66909] Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java …
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage …
M Alto vulnerabilidad
06/08/2026
Inyección de comandos OS en Shibby Tomato 1.28.0000 permite ejecución remota
Se identificó una vulnerabilidad de inyección de comandos en Shibby Tomato 1.28.0000 que afecta la función new_qoslimit_stop en /tmp/qoslimittc_stop.sh. Un atacante remoto puede manipular el parámetro wan_iface para ejecutar comandos del sistema operativo con privilegios del dispositivo. El exploit es público y activamente utilizado. Nota: Este proyecto ha sido descontinuado en favor de FreshTomato.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de control de acceso en CatchPulse permite escalada de privilegios local
Una falla de control de acceso impropio en CatchPulse permite que usuarios locales no administrativos se conecten a un puerto de comunicación del kernel sin restricciones, eludiendo las políticas de seguridad del producto. Esta vulnerabilidad afecta principalmente a entornos corporativos con acceso local compartido, común en infraestructuras LATAM con estaciones de trabajo de uso múltiple.
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica CVE-2026-5430 en autenticación JWT permite acceso no autorizado
Múltiples fabricantes han reportado una vulnerabilidad crítica (CVSS 10.0) en mecanismos de autenticación JWT que aceptan tokens firmados con algoritmos no configurados explícitamente. Atacantes pueden falsificar tokens JWT con algoritmos alternativos que son validados incorrectamente, permitiendo acceso no autorizado a sistemas, bases de datos y controles administrativos. Este riesgo es especialmente grave en infraestructuras cloud, plataformas de API y soluciones de identidad ampliamente usadas en LATAM.