Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
[CVE-2024-42002] A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topi…
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is…
M Crítico vulnerabilidad
27/09/2026
Inyección Eval crítica en hMailServer 6.0.0-6.3.3 permite ejecución remota de código
Una vulnerabilidad crítica (CVSS 9.8) en el despachador de scripts JScript de hMailServer permite a atacantes no autenticados ejecutar código arbitrario con privilegios de servicio. La falla se activa mediante contraseñas manipuladas con secuencias de escape en autenticación SMTP, POP3 e IMAP. Afecta principalmente a servidores de correo en Windows en organizaciones de México y LATAM que usen versiones 6.0.0 a 6.3.3.
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta de ejecución remota de código en MONAI hasta versión 1.6.0
MONAI versiones 1.6.0 y anteriores contienen una vulnerabilidad de ejecución remota de código (RCE) en el motor de configuración de bundles que permite a atacantes ejecutar código arbitrario sin validación de lista permitida. Los agresores pueden distribuir bundles maliciosos con configuraciones manipuladas que se ejecutan cuando usuarios cargan bundles mediante monai.bundle.load(), afectando laboratorios de investigación médica y centros de datos en LATAM que implementan pipelines de procesamiento de imágenes médicas.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100842] MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/b…
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-57149] plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as …
plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() …
M Crítico vulnerabilidad
18/09/2026
[CVE-2025-53837] XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki sy…
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63325] Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version …
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-61667] DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0…
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to DatasetManager.py __checkDataset, where datasetName is interpolated into an FC_MetaDatasets SQL query without parameterization. The injected query ca…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-45579] DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0…
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to RequestManagementSystem/DB/RequestDB.py getRequestCountersWeb. An unrecognized value is resolved against the Request …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19780] Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac…
Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 8081 by default. The issue results from the lack of proper validation of a user-supplied string befo…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82789] An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exis…
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-80351] Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability…
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. …
M Alto vulnerabilidad
08/09/2026
[CVE-2026-76190] ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('E…
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-48273] ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('E…
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-79678] A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-…
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via me…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-19295] IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operatin…
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing …
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-54569] SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.…
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many,…
M Alto vulnerabilidad
23/08/2026
Vulnerabilidad de inyección de código en CHIRP permite ejecución remota vía archivos CSV malformados
CHIRP (chirpmyradio) versiones anteriores a 39178db contiene una vulnerabilidad de inyección eval en el controlador Kenwood ITM que permite a atacantes ejecutar código arbitrario mediante archivos CSV especialmente diseñados. Esto afecta a operadores de radiocomunicaciones y empresas que utilizan esta herramienta para configuración de equipos en México y Latinoamérica.
M Crítico vulnerabilidad
21/08/2026
[CVE-2026-61539] Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and …
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a tools field flow through xinference/api/restful_api.py, xinference/model/llm/transfor…
M Crítico vulnerabilidad
21/08/2026
[CVE-2026-77810] In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain ac…
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.