Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3106 resultados ✕ Limpiar búsqueda
13,734
Total alertas
3105
Críticas
10357
Altas
8
Ransomware
1762
Esta semana
RSS
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta en openssl_encrypt: derivación de claves débil permite cracking de contraseñas (CVE-2026-74888)
openssl_encrypt versiones anteriores a 1.4.0 implementan una construcción PBKDF2 no estándar con iteraciones=1 por llamada, debilitando significativamente la derivación de claves. Atacantes pueden comprometer archivos cifrados legacy con esfuerzo computacional reducido. Afecta sistemas que protegen datos financieros, médicos y personales en empresas mexicanas y latinoamericanas que usan esta librería para cifrado de datos en reposo.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt anterior a v1.4.0 debilita derivación de claves criptográficas
Las versiones de openssl_encrypt anteriores a 1.4.0 implementan HKDF sin salt y parámetros estáticos en funciones de normalización de claves, reduciendo la entropía en la extracción criptográfica. Atacantes pueden explotar la derivación predecible de claves para comprometer la seguridad en ataques multi-objetivo contra sistemas que procesen transacciones financieras, datos de autenticación o comunicaciones sensibles en empresas mexicanas y latinoamericanas.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt anteriores a 1.4.0 permite filtración de secretos
openssl_encrypt en versiones anteriores a 1.4.0 contiene una vulnerabilidad (CVSS 9.8) en la función PublicKeyBundle.from_dict() que procesa datos no verificados sin validar firmas criptográficas. Un atacante puede manipular bundles de claves públicas para cifrar datos con claves controladas por el atacante, exponiendo información sensible en bases de datos, sistemas de pago y plataformas cloud comúnmente utilizadas en LATAM.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74879] openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready …
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74880] openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and…
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74882] openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the enti…
openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is relaxed or modified.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74883] openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbo…
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74868] SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service…
SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTransport.RoundTrip() in kernel/server/proxy/publish.go). The Publish Service runs on a separate, unauthenticated-by-default listener (default TCP port 6808) and gates named publish-viewer accounts (Conf.Publish.Auth.Accounts) with Basic Auth that has no rat…
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74872] openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl…
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74874] openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographi…
openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations containing hidden data for extraction.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74799] SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps w…
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74800] SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin…
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74801] SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin…
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74802] SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-onl…
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally return true. Attackers can craft malicious webpages that establish WebSocket connections to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to attac…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74845] Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulner…
Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
? Crítico alerta
17/08/2026
CISA Adds One Known Exploited Vulnerability to Catalog 
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog . CVEs relacionados: CVE-2025-62593.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19982] A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability af…
A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component Firewall-management RPC. The manipulation of the argument dest_port/dest_ip leads to os command injection. The attack may be initiated remotely. Upgrading to version 4.9.0 is able to resolve this issue. The affected component should be upgraded. The vendor explain…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19983] A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE…
A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulation results in os command injection. The attack may be launched remotely. Upgrading to version 4.9.0 is capable of addressing this issue. It is suggested to upgra…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19980] A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE930…
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated re…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19981] A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE…
A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument switch_power/restore_power can lead to os command injection. The attack can be launc…