Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ni" — 2107 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92397] A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerabilit…
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61595] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61593] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin check, so a cross-origin page could drive a victim-cookie-authenticated SSE session: force the victim's browser to GET the stream URL (which creates and mounts a L…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-17526] Keycloak is an open-source identity and access management solution. A vulnerability was discovered w…
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
M Crítico vulnerabilidad
16/09/2026
[CVE-2025-59953] LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in ver…
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitiz…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92366] A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part…
A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92380] A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRem…
A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes server-side request forgery. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early t…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-84997] react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.…
react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every iteration. An incomplete terminal-chunk trailer without CRLF left the buffer unchanged after strpos retur…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-82964] Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows …
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63128] RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's statef…
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-formed JSON-RPC POST that is not an initialization request, or an initialization request with a mismatched protocol header, causing StreamableHttpService::handle_pos…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-18212] A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity an…
A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zlib memory after use. An unauthenticated attacker can exploit this by sending repeated malformed SAML requests, leading to native memory exhaustion and a denial of …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92466] zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where th…
zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated users with no roles can access administrative APIs including user management, role assignment, and Elasticsearch index operations by bypassing the disabled authorizati…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92467] zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in…
zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92362] A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the fi…
A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attack is possible to be carried out remotely. The pull request to fix this issue awaits acceptance.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92134] Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results…
Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job configuration is submitted through the REST API, allowing attackers with Item/Configure permission to use a javascript: scheme URL as identifier, resulting in a stored cross-site scripting (XSS) vulnerability.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92127] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpat…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through the REST API or CLI, allowing attackers able to define classpath entries to execute arbitrary code in the context of the Jenkins controller JVM.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89028] MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB d…
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61590] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only `DEBUG`. In the misconfigu…
M Alto vulnerabilidad
16/09/2026
Inyección SQL en WP Mega Menu permite acceso no autorizado a bases de datos
Se ha identificado una vulnerabilidad de inyección SQL ciega (CVSS 7.6) en el complemento WP Mega Menu para WordPress, versiones hasta 1.4.2. Empresas que utilizan este plugin en sitios de comercio electrónico, portales corporativos y aplicaciones con datos sensibles en México y LATAM están expuestas a extracción no autorizada de información de bases de datos. Un atacante remoto puede ejecutar comandos SQL maliciosos sin autenticación.
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad de autorización en yshop-crm 2.1.3 expone políticas de reciclaje de clientes
yshop-crm versiones hasta 2.1.3 no valida permisos en los endpoints saveRedisSet y getRedisSet del controlador CrmCustomerController, permitiendo que usuarios autenticados del back-office lean y modifiquen políticas altas de asignación de leads y reciclaje automático de clientes a nivel de instalación. Empresas en LATAM que usan esta plataforma de CRM enfrentan riesgo de manipulación masiva de datos de clientes y comportamientos de negocio automatizados mediante modificación de claves Redis compartidas.