Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-107807] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts …
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment …
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103097] An API key is hardcoded and retrievable from the application package. Since Android applications can…
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103096] API key is hardcoded and retrievable from the application package. Since Android applications can be…
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-81321] CM2507 IP cameras store configured wireless network credentials in cleartext within the device files…
CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-4130] There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulner…
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-83551] Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in …
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipe…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81683] openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client privat…
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system access can read the exposed private key. Version 1.4.9 writes the PEM to a dedicated 0600 file, keeps onl…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-15065] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security r…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66782] A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-li…
A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl get` commands could obtain this token. The possession of this token grants full control over the mesh network, enabling un…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-20312] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information …
M Alto vulnerabilidad
05/08/2026
[CVE-2026-55997] Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream …
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster.
M Crítico vulnerabilidad
04/08/2026
Vulnerabilidad crítica en HUMANIST Digital Human Resources: almacenamiento en texto plano e inyección SQL
HUMANIST Digital Human Resources (versiones 26.0 a 26.0.x) contiene una vulnerabilidad crítica (CVSS 9.8) que permite el almacenamiento de información sensible en texto plano y inyección SQL. Esta falla afecta directamente sistemas de gestión de recursos humanos en empresas LATAM, exponiendo credenciales, datos de nómina y información personal de empleados. La vulnerabilidad es explotable remotamente sin autenticación previa.
M Alto vulnerabilidad
23/07/2026
[CVE-2024-58023] Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to acc…
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
M Alto vulnerabilidad
11/06/2026
[CVE-2026-46622] SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authe…
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconfigured replica, or insider access — immediately obtains all API credentials for every user with no f…
M Alto vulnerabilidad
04/06/2026
[CVE-2026-36176] GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plain…
GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.