Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 25 min
Buscando: "Ni" — 2104 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11375] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11378] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11381] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10030] IBM MQ Console allows authenticated non-administrative users to create and start queue managers due …
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10575] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate pr…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heap buffer overflow when processing MQPUT operations with malformed distribution headers.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10744] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-10747] IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute a…
IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2025-61682] Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query dat…
Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10027] IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a…
IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow when processing malformed compressed data on channels configured with compression enabled.
M Alto vulnerabilidad
18/09/2026
[CVE-2025-14753] IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An…
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93659] Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escapi…
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93558] Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service
Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93604] vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embed…
vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The builtin sanitizer (sanitizeCryptoModule in lib/builtin.js) replaces crypto.setEngine but leaves crypto.setFips callable, and the readonly wrapper used to expose the host module does not localize side effects…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93605] vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTIN…
vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary commands on the host system when NodeVM is configured with builtin:['*'] or explicit child_process allowance.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93606] vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedde…
vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromiseCallback / normalizeHostPromiseCallbacks in lib/bridge.js) only wraps `then`/`catch` rejection slots that hold a function, and the sandbox-side `Symbol.species`/`…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93599] rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reacha…
rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_bits.len() - 1 underflows on the empty slice and the subsequent index operation panics (subtract-with-overflow in debug,…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93594] ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-reco…
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user who is denied readRecord/deleteRecord on a type can still, with a single ordinary …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93560] STOMP codec content-length long-to-int truncation causes infinite decode loop DoS
STOMP codec content-length long-to-int truncation causes infinite decode loop DoS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93491] A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vul…
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad alta en Netty permite agotamiento de memoria por streams SPDY ilimitados
Se identificó una flaw en Netty donde SpdySessionHandler acepta un número ilimitado de streams SPDY concurrentes iniciados remotamente, permitiendo a atacantes enviar múltiples frames SYN_STREAM y causar agotamiento de memoria heap y directa en la JVM. Esto afecta aplicaciones Java que utilizan Netty para comunicaciones HTTP/2 y SPDY, siendo alta en servidores de aplicaciones, gateways y proxies desplegados en infraestructuras cloud y on-premise en LATAM.