Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-28190] Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
Subscriber Broken Access Control in ProLancer Element
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-28153] Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notificatio…
Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-19200] The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other is…
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad de divulgación de información en Combodo iTop anterior a versión 3.2.3
Combodo iTop, herramienta web de gestión de servicios TI utilizada en empresas mexicanas y latinoamericanas, presenta una vulnerabilidad que permite a usuarios no autorizados acceder a información de objetos mediante operaciones de búsqueda. La falla afecta versiones anteriores a 3.2.3 con severidad CVSS 8.8, comprometiendo la confidencialidad de datos sensibles de configuración y activos.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-75932] Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom doma…
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad de autorización en API de Reconmap permite acceso no autenticado a reportes
Reconmap presenta una falla en su política de autorización que permite a usuarios anónimos acceder a la acción PreviewReport en ReportsController.cs, eludiendo el requisito de autenticación administrativa. Esta vulnerabilidad (CVSS 7.5) afecta directamente a empresas que utilizan Reconmap para pentesting y análisis de seguridad, exponiendo reportes confidenciales de evaluaciones de vulnerabilidades.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-76633] WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a…
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routin…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
Control de Acceso Roto sin Autenticación en EPROLO Dropshipping <= 2.4.2
Se ha identificado una vulnerabilidad de control de acceso roto sin autenticación en EPROLO Dropshipping versiones 2.4.2 y anteriores, con puntuación CVSS de 7.1. Esta falla permite a actores no autenticados acceder a funcionalidades sensibles del sistema, comprometiendo datos de inventario, pedidos y configuraciones altas de tiendas dropshipping en México y Latinoamérica. El impacto es significativo para PyMEs que dependen de esta plataforma para sus operaciones de comercio electrónico.
M Alto vulnerabilidad
Hace 3 días
Control de acceso roto sin autenticación en Koji versiones <= 2.2.1
Se ha identificado una vulnerabilidad de control de acceso quebrantado en Koji
M Alto vulnerabilidad
Hace 3 días
Control de acceso roto sin autenticación en Chaplin versiones ≤ 2.6.8
Se ha identificado una vulnerabilidad de control de acceso roto que permite a atacantes no autenticados acceder a funcionalidades restringidas en Chaplin versión 2.6.8 y anteriores (CVSS 7.5). Las empresas en LATAM que ejecuten este framework deben evaluar inmediatamente su exposición, especialmente en aplicaciones web internas y públicas. Este tipo de vulnerabilidad puede comprometer datos sensibles y operaciones altas sin requerir credenciales válidas.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76394] In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "p…
In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The missing authorization is possible because multiple REST API handlers in Splunk AI Toolkit do not enforce authorization chec…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76336] In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "powe…
In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete all Search Processing Language 2 (SPL2) modules across all apps and users on the instance through the SPL2 module management Representational State Transfer (REST) API. This could delete exported datasets and functions, affect system integrity, and cause partial service …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76319] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that d…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Federated Search dispatch flow accepts caller…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76251] In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin"…
In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make lim…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-53547] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/export endpoint creates a user export that includes the global settings table even though the rest of the export is user-scoped. The settings table contains reset_code_ and temp_reset_token_ password-reset artifacts, allowing a low-privileged authenticate…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-18544] IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image polic…
IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16930] IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 i…
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the host system. An attacker with service account or root access to the BMC/FSP can execute arbitrary code on the host system, giving full control over the host system and all hosted partitions, resulting in a confidentiality, in…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-62666] Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont…
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target check used by sibling user mutation endpoints. A non-super account with api.users.write can mint an API key bound to an access.api.super target through requireApi…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-62667] Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's cont…
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin ApiKeyManager::generateKey() stores a declared scopes array, but ApiKeyAuthenticator::authenticate() does not read keyData[scopes] and returns the owning user's complete identity. AbstractApiController::requirePermission() consequently evaluates the full user…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-58565] Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A…
Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.