Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 14 min
Buscando: "Perl" — 489 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81994] Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes (…
Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious fi…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78626] The Okta Access Gateway improperly handles input sanitization and regular expression evaluation with…
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86730] Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allow…
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject().
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en SIMOVE Fleetmanager y SIPLANT afecta gestión de flotas
Se identificó una vulnerabilidad de validación en múltiples versiones de SIMOVE Fleetmanager (V3.1, V3.2, V3.3, V4.0) y SIPLANT (V1.7 a V3.1) con CVSS 8.6. Empresas de logística, transporte y distribución en LATAM que utilicen estas plataformas de gestión de flotas enfrentan riesgo de explotación remota. Se requiere actualización inmediata a versiones parcheadas.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en Reyrolle 7SR5 permite denegación de servicio remota
Se identificó una falla en el servidor web de Reyrolle 7SR5 (versiones anteriores a V2.70) que no limita adecuadamente los recursos del sistema al procesar múltiples solicitudes HTTP concurrentes. Un atacante no autenticado puede explotar esta vulnerabilidad para causar el colapso y reinicio del dispositivo, interrumpiendo sistemas altas de protección en subestaciones eléctricas. En LATAM, donde estos relés protegen infraestructura eléctrica esencial, el impacto operacional es severo.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta de escalada de privilegios en Reyrolle 7SR5 (CVSS 8.8)
Se ha identificado un fallo en los controles de autorización del lado del servidor en la interfaz de gestión web de Reyrolle 7SR5 en todas las versiones anteriores a V2.70. Un atacante autenticado con permisos bajos puede eludir las restricciones de control de acceso basado en roles (RBAC) manipulando datos de solicitudes para escalar privilegios a nivel administrativo. Esto afecta directamente a infraestructuras altas de distribución eléctrica y subestaciones en LATAM que dependen de estos dispositivos de protección.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62648] A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL c…
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denia…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en PocketMine-MP anterior a 4.7.2 permite negación de servicio
PocketMine-MP versiones anteriores a 4.7.2 no maneja adecuadamente excepciones de la librería adhocore/json-comment al procesar datos de geometría de skins. Atacantes pueden enviar paquetes de inicio de sesión o skin malformados para provocar una excepción no controlada que causa el colapso del servidor. Este fallo afecta directamente a servidores de juego en México y Latinoamérica que dependen de PocketMine-MP para Minecraft Pocket Edition.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad alta en OpenPanel anteriores a 2.3.0 permite ejecución de código remoto
OpenPanel versiones anteriores a 2.3.0 contiene una falla en la validación de expresiones de fórmulas en gráficos que permite a miembros autenticados del proyecto con acceso de lectura ejecutar código arbitrario. Los atacantes pueden recuperar el constructor nativo de JavaScript a través de objetos matriz de mathjs, cargar módulos de Node.js y ejecutar comandos del sistema operativo con privilegios del proceso API, comprometiendo completamente la infraestructura.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85433] MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing …
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85394] python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepti…
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85396] rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fail…
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85388] Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helpe…
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for …
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80465] A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), M…
A vulnerability has been identified in Mendix SAML (Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < V3.6.27). Affected versions of the module do not properly validate the SAML response signature. This could allow unauthenticated remote attackers to hijack an account (session) in specific…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84838] A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to e…
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-4357] The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files vi…
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19723] The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properl…
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPr…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84694] Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands exec…
Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81928] Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data w…
Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs a message by re-encoding it, and removes TSIG records only from the additional section. A TSIG decoded into the answer or authority section survives that step and is signed again, so encoding re-enters sig_data with no terminati…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84482] WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_d…
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.