Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
L Crítico vulnerabilidad
02/06/2026
[CVE-2026-32625] LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and in…
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-co…
G Crítico vulnerabilidad
02/06/2026
[CVE-2026-49448] authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, …
authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This issue has been patched in versions 2025.12.6, 2026.2.4, and 2026.5.1.
G Crítico vulnerabilidad
02/06/2026
[CVE-2026-42849] authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the …
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages in the SFE (Simple Flow Executor) in order to make the interface more compatible with legacy browsers, it was possible to use an XSS exploit in the AutosubmitStage. This issue has been patched in versions 2025.12.5 and 2026.2.3.
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-5076] The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in a…
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. Th…
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-38967] CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response…
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
G Crítico vulnerabilidad
02/06/2026
[CVE-2026-42074] OpenClaude is an open-source coding-agent command line interface for cloud and local model providers…
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to true in any tool_use response. Combined with the default allowUnsandboxedCommands: true setting…
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-0611] Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthe…
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achiev…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-47117] OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model …
OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path that loads Hugging Face models with trust_remote_code=True. An unauthenticated attacker can supply a m…
P Crítico vulnerabilidad
02/06/2026
[CVE-2026-7198] CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 a…
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations.
P Crítico vulnerabilidad
02/06/2026
[CVE-2026-7312] CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14…
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requi…
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-10611] An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with…
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=true, users authenticated through an authentication plugin, such as LDAP, may have their authenticated session established during the application beforeFilter phase before the normal login flow enforces…
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-42684] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.
M Crítico vulnerabilidad
02/06/2026
[CVE-2025-53209] Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalat…
Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue affects Masteriyo LMS PRO: from n/a through 2.20.0.
M Crítico vulnerabilidad
02/06/2026
Vulnerabilidad crítica de ejecución remota de código en Microsoft Outlook y Word (CVE-2026-40361)
Microsoft ha publicado un advisory de seguridad sobre una vulnerabilidad de ejecución remota de código (RCE) que afecta a Microsoft Outlook y Word. Un atacante remoto podría ejecutar código arbitrario en sistemas afectados mediante documentos o correos electrónicos especialmente diseñados. Esta vulnerabilidad representa un riesgo crítico para organizaciones en México y Latinoamérica que dependen de estas herramientas de productividad en sus operaciones diarias.
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-8206] The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t…
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Crítico vulnerabilidad
28/05/2026
Vulnerabilidad crítica en Android OS (CVE-2026-9872) – CVSS 9.6
Google publica parche para vulnerabilidad crítica en Android OS con puntuación CVSS 9.6 que afecta más del 80% del parque móvil en México y Latinoamérica. La falla permite comprometer la seguridad del dispositivo y acceso no autorizado a datos sensibles. La actualización está disponible en Ajustes > Actualización del sistema.
G Crítico vulnerabilidad
28/05/2026
Vulnerabilidad crítica en Android OS (CVE-2026-9875) - CVSS 9.6
Se ha identificado una vulnerabilidad de severidad crítica en Android OS con puntuación CVSS de 9.6 que afecta a más del 80% de dispositivos móviles en México y Latinoamérica. Esta falla compromete la seguridad de millones de usuarios corporativos y personales en la región, requiriendo actualización inmediata para prevenir explotación remota.
G Crítico vulnerabilidad
28/05/2026
Vulnerabilidad crítica Use-After-Free en Android OS (CVE-2026-9876) — CVSS 9.6
Se ha identificado una vulnerabilidad de Use-After-Free (UAF) de severidad crítica en Android OS con puntuación CVSS 9.6. Esta afecta a más del 80% de los dispositivos móviles en circulación en México y Latinoamérica, exponiendo millones de usuarios a ejecución de código remoto. La explotación de este defecto permite a atacantes comprometer dispositivos sin interacción del usuario.
G Crítico vulnerabilidad
26/05/2026
Vulnerabilidad crítica de Ejecución Remota de Código en Microsoft Edge (Chromium)
Se ha identificado una vulnerabilidad de ejecución remota de código (RCE) en Microsoft Edge basado en Chromium que permite a atacantes ejecutar código arbitrario en sistemas afectados. Este tipo de vulnerabilidad representa un riesgo crítico para empresas en México y Latinoamérica que utilicen Edge como navegador corporativo, especialmente en entornos de acceso a información sensible o sistemas financieros. La explotación no requiere interacción del usuario más allá de navegar a un sitio web malicioso.
? Crítico vulnerabilidad
26/05/2026
Vulnerabilidad crítica de Ejecución Remota de Código en Microsoft Defender (CVE-2026-45584)
Microsoft Defender contiene una vulnerabilidad de ejecución remota de código que permite a atacantes ejecutar código arbitrario en sistemas comprometidos sin autenticación. Esta falla afecta directamente a empresas en México y Latinoamérica que dependen de Defender como solución de protección endpoint, exponiendo servidores y estaciones de trabajo a ataques críticos. La severidad de RCE en un producto de seguridad amplifica significativamente el riesgo de infiltración en infraestructuras corporativas.