Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82393] pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a t…
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-re…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82598] A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file se…
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-19286] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18729] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82278] BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoin…
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() without sandboxing, gaining access to filesystem, credentials, and internal network resources.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55565] Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getV…
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompiler.cook instead of applying ValueExpression.escapeJavaString. The pattern can originate from POST /…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55634] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55559] Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from PO…
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. The rendered configuration is parsed by YamcsServer.createInstance and loaded by YamcsServerInstance, allowing…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55511] Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPri…
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and Expression.sanitizeName. A sum aggregate reaches yamcs-core/src/main/java/org/yamcs/yarch/streamsql/CompilableAggregateExpression.java and y…
M Crítico vulnerabilidad
28/08/2026
Vulnerabilidad crítica de ejecución remota de código en Budibase anterior a v3.41.3
Budibase versiones anteriores a 3.41.3 contienen una vulnerabilidad de ejecución remota de código (RCE) en el manejo de plugins que permite a usuarios administradores autenticados ejecutar código arbitrario mediante la carga de un tarball malicioso. El servidor ejecuta eval() en archivos JavaScript de plugins sin aislamiento en el proceso Node.js principal, habilitando la exfiltración de variables de entorno y credenciales con privilegios root. Empresas en LATAM que utilicen Budibase en entornos de producción o desarrollo enfrentan riesgo crítico de compromiso total del servidor.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-54721] Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4…
Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to configure a UserForms email recipient can use the subject field to run arbitrary code o…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81719] openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the …
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import time, before the runtime sandbox is installed. The only default gate was an incomplete, bypassable AST denylist. If a user is induced to load an attacker…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81096] ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that req…
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup builtins available and did not stop a dunder attribute reached through a string lookup o…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-19223] The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network adminis…
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58474] whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that …
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The script generation function in cli.py interpolates HuggingFace-derived values, including GGUF variant file…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-74851] The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its …
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-76148] CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the…
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-57170] Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc…
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template code in a non-sandboxed environment, allowing server-side template injection that can lead to arbitr…
M Alto vulnerabilidad
25/08/2026
Inyección de plantillas en Compliance-trestle permite ejecución remota de código
Compliance-trestle (versiones anteriores a 3.12.4 y 4.0.0-4.0.3) contiene una vulnerabilidad de inyección de plantillas del lado del servidor en las etiquetas Jinja2 MDCleanInclude y MDSectionInclude. Un atacante puede ejecutar código arbitrario reparseando contenido Markdown no confiable como código fuente de plantilla. Afecta a organizaciones que utilizan Trestle para gestionar documentos de cumplimiento OSCAL en México y LATAM.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65082] NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker …
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.