Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Rti" — 222 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-46352] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentation code could deadlock when processing fragmented traffic containing an encapsulated tunnel protocol whose payload is itself fragmented. Version 8.0.5 contains a fix. No known workarounds are available…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92720] Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowi…
Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored credentials and register malicious webhooks to intercept pipeline events or suppress alerting by deleting existing configurations.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-85731] oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of…
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTarDirectory and ensureLinkPath validates symlink targets lexically, resolveRelToBase skips its parent-symlink walk for root-level entries, and writeFile follows a …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-42784] A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates…
A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an attacker to bypass the back-signature check. Consequently, an attacker can illegitimately bind an arbitrary subkey to their own certificate and forge signatures, com…
M Crítico vulnerabilidad
16/09/2026
[CVE-2025-59953] LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in ver…
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitiz…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76163] If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker …
If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and 9.20.9-S1 through 9.20.27-S1.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-81736] If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the ro…
If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad de autorización en yshop-crm 2.1.3 expone políticas de reciclaje de clientes
yshop-crm versiones hasta 2.1.3 no valida permisos en los endpoints saveRedisSet y getRedisSet del controlador CrmCustomerController, permitiendo que usuarios autenticados del back-office lean y modifiquen políticas altas de asignación de leads y reciclaje automático de clientes a nivel de instalación. Empresas en LATAM que usan esta plataforma de CRM enfrentan riesgo de manipulación masiva de datos de clientes y comportamientos de negocio automatizados mediante modificación de claves Redis compartidas.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-90012] In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership …
In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failure If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps TX but leaves tx_sg_mapped set. If TX mapping fails on a later transfer, mappings created for earlier transfers remain active. In both cases, cur_{tx,rx}_dma_dev have not yet been updated because they are …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89922] In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when impor…
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data __import_wp_info() backs up the original guest memory contents of a watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or kvm->slots_lock) to be held, otherwise a concurrent memslot updat…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-89916] In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidat…
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry A VNCR TLB invalidation can occur on one vcpu while another vcpu is faulting in this same page. Without correctly handling this, we can end up with the following scenario: - vcpu A walks the PTs to translate VNCR - before vcpu A is able to grab the MMU loc…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89856] In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X deri…
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and ha->max_qpairs are u8. Deriving the queue count as "ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board (or a misconfigured/malicious hot-plugged device) advertising 257 MSI-…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89823] In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial d…
In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial drm_dev_register() failure and ioctl If drm_dev_register() fails after registering a minor (e.g. render minor registered, primary minor fails), userspace could have opened the first minor and entered a drm_dev_enter() critical section. Since the unplugged flag was never set, the ioctl proceeds while…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89814] In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation…
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation index for rings outside a partition adev->isolation[] has one slot per partition, but a ring that is not assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing the array with it is out of bounds. SDMA submissions hit this on both the isolation enforcement and the VM flush path and…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-89781] In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds rea…
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buf() read_log_rec_buf() copies a log record into a caller buffer starting at u32 off = lsn_to_page_off(log, lsn) + log->record_header_len; log->record_header_len (and log->data_off, used for the following pages) comes verbatim from the on-disk restart area and is only checked …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad alta en Arista EOS con gNSI permite escalada de privilegios (CVE-2026-73454)
Plataformas Arista EOS con interfaz gRPC Network Security Interface (gNSI) Credentialz configurada son vulnerables a solicitudes especialmente diseñadas que modifican propiedades de cuentas de usuario. Un atacante podría asignar privilegios elevados a cuentas existentes, comprometiendo el control de acceso en infraestructura de red alta. El impacto afecta directamente a proveedores de servicios y centros de datos en LATAM que dependen de equipos Arista para segmentación y control de tráfico.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-73446] On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthen…
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91939] Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes r…
Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted serialized payloads to trigger gadget chains and achieve database manipulation or code execution.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61559] `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and …
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base URL for all outbound GitLab API calls made within that request. The server validates that the value is a well-formed URL (`…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88975] Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read l…
Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s 24-bit declared length but waits to buffer the entire payload before comparing it with SETTINGS_MAX_FRAME_SIZE. An unauthenticated peer can declare a payload near 16 MiB on a connection where Ember advertised 16 KiB and either complete or slowly stream it, causing up to 1024-fol…