Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad
30/09/2026
Bypass de autenticación por inyección LDAP en Apache MINA SSHD afecta múltiples versiones
Apache MINA SSHD, biblioteca Java para SSH, contiene una vulnerabilidad crítica (CVSS 9.1) en su componente opcional sshd-ldap que permite eludir autenticación mediante inyección LDAP. Las versiones afectadas incluyen 1.2.0 a 2.19.0 y 3.0.0-M1 a 3.0.0-M5. Empresas en LATAM que integren LDAP para autenticación SSH en servidores están expuestas a acceso no autorizado.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19271] Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability i…
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This issue affects Liderahenk: from 3.4.0 before 3.5.5.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-11770] A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search …
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication …
M Alto vulnerabilidad
30/07/2026
[CVE-2026-58222] A security flaw combining LDAP filter injection and improper authorization checks was found in Samba…
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted context, bypassing normal Access Control List (ACL) enforcement. An authenticated low-pr…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47303] Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to ele…
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
09/07/2026
[CVE-2026-4256] Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability i…
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026.
M Alto vulnerabilidad
07/07/2026
[CVE-2026-13696] Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability i…
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman MYS: before release.Master.1107.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Crítico vulnerabilidad
17/06/2026
[CVE-2026-49268] A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction i…
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonati…