Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Fortinet" — 84 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1015
Esta semana
RSS
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-104286] An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F…
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-84388] A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Ext…
A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticated attack
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-84390] A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.…
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84387] A improper neutralization of special elements used in a command ('command injection') vulnerability …
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84393] A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 thro…
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-26084] A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4…
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
F Medio vulnerabilidad
08/09/2026
Arbitrary process termination from exposed minifilter communication port
Fortinet PSIRT publica advisory de seguridad: Arbitrary process termination from exposed minifilter communication port. Tipo: Vulnerabilidad de seguridad. Producto afectado: Forticlient.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
F Alto vulnerabilidad
08/09/2026
Broken Access control on Websocket streams
Fortinet PSIRT publica advisory de seguridad: Broken Access control on Websocket streams. Tipo: Control de Acceso Inadecuado. Producto afectado: Fortisoar.
F Medio vulnerabilidad
08/09/2026
Cron Job Injection in Remote Backup
Fortinet PSIRT publica advisory de seguridad: Cron Job Injection in Remote Backup. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortisandbox.
F Crítico vulnerabilidad
08/09/2026
JWT used for authentication in web GUI signed with static key
Fortinet PSIRT publica advisory de seguridad: JWT used for authentication in web GUI signed with static key. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortimonitor.
F Medio vulnerabilidad
08/09/2026
Null Pointer Dereference in Log Report
Fortinet PSIRT publica advisory de seguridad: Null Pointer Dereference in Log Report. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortios.
F Medio vulnerabilidad
08/09/2026
Open Redirect on FortiSIEM
Fortinet PSIRT publica advisory de seguridad: Open Redirect on FortiSIEM. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortisiem.
F Crítico vulnerabilidad
08/09/2026
Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information
Fortinet PSIRT publica advisory de seguridad: Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information. Tipo: Control de Acceso Inadecuado. Producto afectado: Fortisandbox.
F Crítico vulnerabilidad
08/09/2026
Uncontrolled Resource Consumption in SNMP
Fortinet PSIRT publica advisory de seguridad: Uncontrolled Resource Consumption in SNMP. Tipo: Denegación de Servicio (DoS). Producto afectado: Fortianalyzer.
F Alto vulnerabilidad
08/09/2026
Workflow session email approval process bypass
Fortinet PSIRT publica advisory de seguridad: Workflow session email approval process bypass. Tipo: Control de Acceso Inadecuado. Producto afectado: Fortimanager.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
F Crítico vulnerabilidad
08/09/2026
ZTNA Portal Improper Certificate Validation
Fortinet PSIRT publica advisory de seguridad: ZTNA Portal Improper Certificate Validation. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortios.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-70468] A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.…
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-26035] An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through …
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
M Alto vulnerabilidad
12/08/2026
Desbordamiento de búfer alta en Fortinet FortiClient Windows permite ejecución remota de código
Una vulnerabilidad de desbordamiento de búfer en Fortinet FortiClient Windows (versiones 7.2.0-7.2.11 y 7.4.0-7.4.3) permite a atacantes no autenticados ejecutar código arbitrario manipulando respuestas DNS. El ataque requiere posición en la red para alterar tráfico DNS, afectando principalmente a empresas en LATAM con VPN corporativos que confían en FortiClient para acceso remoto seguro.
F Crítico vulnerabilidad
12/08/2026
Broken access control in the RADIUS type admin group
Fortinet PSIRT publica advisory de seguridad: Broken access control in the RADIUS type admin group. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortiweb.