Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-78019] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusio…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105677] Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost…
Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-12171] auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-change…
auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks…
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-105080] In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes the…
In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100256] In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible…
In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97150] When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.ph…
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-87114] A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrec…
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with r…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-54160] Network UPS Tools is a collection of programs which provide a common interface for monitoring and ad…
Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits 658b24e and 1aa31d1, the GitHub Actions script used to prepare NUT tarballs and update GitHub Checks statuses and PR comments about it was mis-structured in terms of mixing code running with higher privileges (single-use token generated with wr…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-95985] The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated ac…
The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sending any message can cause agent modifications to auto-loaded global configuration paths. We recommend you upgrade to Kiro IDE version 1.0.242 or later. U…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17647] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to execute arbitrary commands due to the inclusion of functionality from an untrusted control sphere.
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93993] Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation p…
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54916] NetBox Device Type Library is a collection of community-sourced device type definitions for import i…
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenticated contributor can add a module such as tests/git.py that shadows GitPython when tests/definition…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54752] NetBox Device Type Library is a collection of community-sourced device type definitions for import i…
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated contributor can change USE_LOCAL_KNOWN_SLUGS in tests/test_configuration.py and supply a c…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86504] In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev …
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de ejecución remota de código en Axolotl hasta versión 0.18.0
Axolotl versiones 0.18.0 y anteriores contienen una vulnerabilidad de ejecución remota de código (RCE) en la ruta de parche multipack. El parámetro trust_remote_code por defecto es None en lugar de False, permitiendo a atacantes eludir los controles de seguridad. Un adversario puede ejecutar código Python arbitrario al comprometer repositorios de modelos en Hugging Face utilizados como base_model, que se cargan con trust_remote_code=True forzado. Esto afecta principalmente a equipos de ML/IA en LATAM que utilizan modelos preentrenados de repositorios públicos sin validación.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-58569] Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. …
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
M Alto vulnerabilidad
26/08/2026
[CVE-2026-18252] GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 bef…
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76139] A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a s…
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to u…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-75569] A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remot…
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to t…
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-22306] Download of code without integrity check, inclusion of functionality from untrusted control sphere, …
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic update channel - OzolsSQL client update path, the _update SQL Server Agent job (@subsystem = N'ActiveScripting') and se…