Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Dify" — 192 resultados ✕ Limpiar búsqueda
13,538
Total alertas
3074
Críticas
10192
Altas
8
Ransomware
1802
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 22 min
[CVE-2026-71933] Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo…
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.
M Crítico vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-78207] exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper t…
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76399] In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app…
In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to mod…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76394] In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "p…
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because multiple REST API handlers in Splunk AI Toolkit do not enforce authorization chec…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76362] In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffi…
In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify all relevant data exchanged through that credential manager. The vulnerability is possible because the CyberArk REST client does not verify server certificates by default. The attack …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76352] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could create or modify a scripted lookup through generic configuration endpoints and run an installed lookup script with the permissions of the user account running Splunk Enterprise, which could allow for access to all relevant data and affect system integrity and a…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16707] IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW95…
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot sta…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-16822] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC p…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-53958] 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an au…
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in server/api/controllers/users/update.js mass assigns these backend-managed identity att…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-66783] A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for K…
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, in…
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-19478] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-73646] PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul…
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sources…
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica de omisión de autenticación en openssl_encrypt anteriores a v1.4.0
openssl_encrypt versiones previas a 1.4.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en pqc.py donde fallos en desencriptación AES-GCM activan una caída no autenticada a modo AES-CTR. Atacantes pueden modificar texto cifrado en tránsito para eludir verificación de integridad y ejecutar ataques de inversión de bits sin detección, comprometiendo confidencialidad e integridad de datos en sistemas financieros, gubernamentales y corporativos de LATAM.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73061] Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al…
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19908] PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows networ…
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19629] A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu…
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19628] A command injection vulnerability exists in Tenable Security Center. An authenticated administrator …
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-16772] In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to …
In Akaunting versions sync()` call without verifying whether the caller is authorized to manage roles. …
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta en File Browser permite acceso no autorizado a archivos de otros usuarios
File Browser versiones anteriores a 2.63.20 contiene una falla de aislamiento en los mecanismos de autenticación por proxy y auto-aprovisionamiento de usuarios. Atacantes con credenciales válidas pueden leer, modificar, eliminar y compartir archivos de otros usuarios al explotar la asignación del scope raíz del servidor. Esta vulnerabilidad afecta especialmente a organizaciones en LATAM que despliegan File Browser en entornos multi-usuario o en arquitecturas de proxy.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72853] Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's p…
Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or modify arbitrary data.