Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-108261] Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /…
Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the Graph…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101152] Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated…
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101090] Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the ne…
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54618] Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize…
Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client. An unauthenticated remote caller who can reach the intended tunnel deployment can therefore call /mcp and use vault_read, …
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-54072] Authorizer is an open-source, self-hostable authentication and authorization server. Prior to versio…
Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-suppl…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88887] Renovate is a dependency update automation tool. When listing tags/digests for a container image, Re…
Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore s…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88880] Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagi…
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88881] Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HT…
Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials configured for that host to the URL given as the 'next' page. Because the pagination URL is not validated against the host originally contacted, a malicious or compromis…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88882] Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE…
Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from a NuGet registry Renovate follows pagination URLs supplied by the registry in the HTTP `Link` header without verifying that the target has the same origin as the c…
M Crítico vulnerabilidad
10/09/2026
Vulnerabilidad de redirección abierta (Open Redirect) en Access Control System de Armiya
Se ha identificado una vulnerabilidad de redirección abierta en Access Control System de Armiya Information Technologies (versiones anteriores a la 2.0) que permite a atacantes redirigir usuarios a sitios no confiables y falsificar la fuente de datos. Esta falla afecta principalmente sistemas de control de acceso implementados en instalaciones de seguridad física en México y Latinoamérica, exponiendo credenciales y sesiones de usuarios autorizados.