Alerta · Publicado 23/04/2026 · Actualizado 26/05/2026
La Agencia de Seguridad de Infraestructuras y Ciberseguridad (CISA) de EE.UU. ha añadido la vulnerabilidad CVE-2026-39987 a su catálogo de vulnerabilidades conocidas y explotadas. Esto indica que existen pruebas de explotación activa en el terreno. Las organizaciones en México y Latinoamérica deben identificar si utilizan productos afectados y aplicar parches de inmediato, dado el alto riesgo de compromiso.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-39987 Marimo Remote Code Execution Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for mo
Alerta publicada por CISA / US-CERT. Consulta el advisory completo para detalles técnicos, indicadores de compromiso y mitigaciones específicas.