Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1263
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102143] An unauthenticated attacker could cause a file with attacker-controlled content to be written to the…
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102147] A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attack…
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102149] Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could b…
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102150] A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauth…
A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set of internal service operations on the Kiteworks platform; it did not permit access to user accounts, stored files, or form submissions.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102127] An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references…
An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they …
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102128] An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act o…
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102129] A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was…
A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102130] Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, …
Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102131] Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did n…
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102132] An administrative import function in Kiteworks Core did not verify that the requesting administrator…
An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102120] A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obt…
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution conte…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102121] A form-rendering interface in the Advanced Forms component is reachable without authentication so th…
A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deploymen…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102123] A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended dire…
A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitation requires network access to the affected interf…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102125] The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the cod…
The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt th…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102126] A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding …
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative co…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102115] Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An u…
Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102116] -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to …
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102117] On deployments where the remote-support capability is licensed and enabled, an authenticated System …
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resultin…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102118] A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an exist…
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102119] A path traversal weakness in an optional, non-default administrative feature allowed an authenticate…
A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.