CiberLATAMbywhalemate

#vulnerabilidades

This archive brings together reporting and analysis on security flaws in software, systems, and services used across Latin America. It covers technical findings, responsible disclosures, patching, active exploitation, and the operational impact these issues can have on public and private organizations in the region.

Ecuador warns of active MikroTik RouterOS flaws

ECUCERT flagged three exploited CVEs in MikroTik RouterOS. Taiwan's NICS-TW and the Dutch DIVD also reported active attacks.

Sep 24, 2026 · 3 min

Cisco confirms CVE-2026-76460 in ISE

Cisco disclosed an auth bypass in ISE and ISE-PIC with active exploitation and no workaround. Patches are required for 3.1 to 3.5.

Sep 18, 2026 · 2 min

CISA adds 7 critical flaws to KEV

CISA added seven vulnerabilities to the KEV, including active exploitation in SonicWall SMA 1000, Kestra OSS, LiteLLM and Sangoma Switchvox.

Sep 12, 2026 · 3 min

CISA adds active PaperCut flaws to KEV

CISA added CVE-2026-81578, CVE-2026-82078, and CVE-2026-82329 to KEV after active exploitation in PaperCut

Sep 6, 2026 · 2 min

Cisco fixes CVE-2026-20212 in Nexus 9000

Cisco patched a critical flaw in Silicon One-based Nexus 9000 switches that allows unauthenticated remote code execution as root.

Sep 4, 2026 · 3 min

CERT.PY warns on Cisco Catalyst SD-WAN flaw

CERT.PY flagged a high-severity issue in Cisco Catalyst SD-WAN. Cisco also patched five flaws in the same round, including three critical ones.

Sep 1, 2026 · 1 min

CERT-PY flags critical Ubiquiti flaws

CERT-PY warned about critical Ubiquiti flaws and said Samba patches are already available. Ubiquiti fixed 22 UniFi vulnerabilities.

Aug 28, 2026 · 3 min

CERT-PY warns on critical Ubiquiti flaws

CERT-PY flagged critical Ubiquiti flaws that could lead to remote code execution, while technical details point to UniFi OS chains.

Aug 18, 2026 · 4 min

Microsoft patches 421 CVEs in August 2026

Microsoft’s August 2026 Patch Tuesday fixes 398 to 421 vulnerabilities, including at least one actively exploited zero-day.

Aug 12, 2026 · 3 min

CISA warns on three SharePoint flaws

CISA says three SharePoint Server on-premises flaws are being actively exploited and urges patching plus tighter hardening.

Jul 19, 2026 · 3 min

INCIBE flags Proteus and ABB industrial flaws

INCIBE warned about three flaws in Proteus and seven in ABB products, including one critical issue, and urged immediate patching.

Jul 9, 2026 · 2 min

INCIBE Warns of Six Citrix NetScaler Flaws

Spain’s national cybersecurity institute warned on July 3, 2026 about six vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

Jul 6, 2026 · 2 min