Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1261
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-74221] U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-com…
U-Boot before 2026.10-rc5 contains a buffer overflow in nfs_readlink_reply() function in net/nfs-common.c when processing NFS server responses. A malicious NFS server can send crafted READLINK replies with negative or oversized symlink length values to corrupt memory and crash the bootloader.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-74222] U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function wi…
U-Boot before 2026.10-rc5 contains a use-after-free vulnerability in the httpc_recv_cb() function within the lwIP wget implementation. When HTTP data storage fails, the callback frees the connection PCB but returns ERR_BUF instead of ERR_ABRT, causing the TCP input path to access released memory and crash the bootloader.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-74225] U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails t…
U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-72507] The "reportType" parameter in the product summary report feature within the balancing reports sectio…
The "reportType" parameter in the product summary report feature within the balancing reports section is susceptible to a time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-72510] The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-bas…
The "supplier_no" parameter used in the business allocation search feature is vulnerable to time-based blind SQL injection.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-71379] The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by …
The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted POST request.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-71971] U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerabilit…
U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-71302] The application accepts user-supplied session identifiers and does not regenerate the session ID aft…
The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-70356] The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attack…
The TMS file upload endpoint fails to enforce server-side file type restrictions, allowing an attacker to upload and execute arbitrary PHP files on the web server.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68954] The "pattern" parameter used in search function in the home page of the TMS application is vulnerabl…
The "pattern" parameter used in search function in the home page of the TMS application is vulnerable to time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68068] The "screenID" parameter in the electronic transaction queue viewer feature within the manual transa…
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-63713] The "search" parameter in the view audit logs feature within the utilities section is susceptible to…
The "search" parameter in the view audit logs feature within the utilities section is susceptible to a time-based blind SQL injection vulnerability.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-94204] The central cloud storage backend for the entire dashcam platform is misconfigured with public-read …
The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-96587] The Viidure Android application embeds permanent, plaintext cloud storage credentials within its com…
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102925] virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the genera…
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish scrip…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102253] iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated…
iperf3 versions prior to 3.22 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash-loop the server's UDP receive worker into an unrecoverable infinite loop by sending a single crafted control-channel parameter message followed by one 16-byte UDP datagram. Attackers can permanently pin the affected per-stream receive thread at approximately 100% CPU usage…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96274] In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink mess…
In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the …
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-79538] metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP i…
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76721] Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that cou…
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-76722] Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant…
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.