Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-102667] Joyland AI app allows an attacker with shared network access to inject JavaScript into content loade…
Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, mi…
M Alto vulnerabilidad
22/09/2026
Escalada de privilegios alta en servidores gRPC mediante función expuesta
Una función peligrosamente expuesta en servidores gRPC permite a atacantes escalar privilegios localmente (CVSS 8.8). Afecta múltiples proveedores y plataformas de microservicios comúnmente desplegadas en infraestructuras cloud de empresas latinoamericanas. Sin parches inmediatos, expone sistemas de APIs, orquestación de contenedores y aplicaciones distribuidas.
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-77521] MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a …
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-68928] Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.r…
Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a binding permission, and src/plugins/terminal/src/android/TerminalService.java does not verify the caller. Any installed Android application can bind the service and send MSG_EXEC with an a…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-20293] A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UC…
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized softw…
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en electerm anterior a 5.3.15 expone funciones del proceso principal
electerm versiones anteriores a 5.3.15 contiene una vulnerabilidad de validación insuficiente en su manejador IPC de Electron que expone más de 40 funciones del proceso principal sin lista de permisos ni validación del remitente. Un atacante puede ejecutar código arbitrario del lado del renderizador para invocar funciones como openFileWithEditor con argumentos maliciosos, permitiendo la ejecución de comandos del sistema con privilegios elevados. Esto afecta a empresas en LATAM que utilizan electerm para administración remota de terminales SSH.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-18262] Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne…
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/08/2026
[CVE-2026-18263] Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne…
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-13121] Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulne…
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the RAS…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-52877] Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to v…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A compromised renderer can submit file: URIs or operating-system-specific custom schemes, causing the host to open local files…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48056] Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions p…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Azure Confidential Ledger permite ejecución de código remoto
Una función peligrosa expuesta en Azure Confidential Ledger permite que atacantes autorizados ejecuten código arbitrario a través de la red, afectando infraestructuras de blockchain y auditoría en empresas LATAM. Con CVSS 9.1, esta vulnerabilidad representa riesgo crítico para sistemas financieros, gubernamentales y de cumplimiento normativo que dependen de ledgers inmutables en Azure.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18901] A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.ad…
A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44107] A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefor…
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
M Alto vulnerabilidad
15/07/2026
[CVE-2026-45805] Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP'…
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to PluginBridge.executePluginTask(), allowing anyone on the network to execute JavaScript on the server. This issue is fixed in version 2.15.0.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-53633] Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vite…
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker…
M Crítico vulnerabilidad
06/07/2026
[CVE-2025-53827] ownCloud Core is the server-side component of the file storage, synchronization, and sharing applica…
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute arbitrary code. This issue has been fixed in version 10.15.3.
A Crítico vulnerabilidad
24/06/2026
[CVE-2026-55454] Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bund…
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is not directly published to the host by docker-compose.yml, it is reachable from the Appsmith server process itself or a SSRF vulnerability. An authentic…
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-41283] OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. The…
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.