Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad SSRF alta en WWBN AVideo permite lectura de archivos locales sin autenticación
WWBN AVideo contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la función _json_decode que permite a atacantes no autenticados enviar rutas de archivos o URLs HTTP a login.json.php para leer archivos locales o acceder a servicios internos. Los resultados se interpretan como credenciales de acceso, exponiendo configuraciones sensibles, bases de datos y tokens de sistemas en empresas de LATAM que utilizan este software para streaming de video.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82097] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81213] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81265] IBM Langflow OSS 1.0.0 through 1.11.5.
IBM Langflow OSS 1.0.0 through 1.11.5.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81207] IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project member…
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller. The ds-canvas pod sits on the OpenShift overlay with reach to co-tenant services, in-cluster CP4D APIs, and link-local address…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89049] A server-side request forgery issue due to improper validation of equivalent address representations…
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role cre…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87999] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's globally routable address classification as proof that a destination was external. An authenticated user could make an Azure-hosted instance fetch and ret…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87996] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public ad…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86771] Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF gene…
Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee_num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or externa…
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad SSRF alta en Lara Dashboard 1.3.1 permite lectura de credenciales IAM
Lara Dashboard versiones hasta 1.3.1 contiene una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en el endpoint POST /api/admin/builder/markdown/fetch. Usuarios autenticados pueden obtener URLs arbitrarias y acceder a servicios HTTP internos, metadatos en la nube e incluso credenciales IAM sin validación de host ni restricciones de redirección. En entornos de AWS, Azure o Google Cloud utilizados por empresas LATAM, esta vulnerabilidad expone acceso directo a tokens de identidad y secretos almacenados en servicios internos.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79635] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80123] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87084] Tanium addressed a server-side request forgery vulnerability in Enforce.
Tanium addressed a server-side request forgery vulnerability in Enforce.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86806] A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within…
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-66304] Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose…
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81357] Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a…
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73315] XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhoo…
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81806] Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side …
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86539] knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embeddin…
knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86273] A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the func…
A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to t…