Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1275
Esta semana
RSS
M Crítico vulnerabilidad
27/08/2026
Inyección de objetos PHP sin autenticación en Geo Controller <= 8.9.8
Se ha identificado una vulnerabilidad crítica (CVSS 9.8) de inyección de objetos PHP sin autenticación en Geo Controller versiones 8.9.8 y anteriores. Un atacante remoto podría ejecutar código arbitrario y comprometer completamente sistemas que utilicen esta extensión, afectando potencialmente aplicaciones web en infraestructuras de empresas y gobiernos en LATAM. La gravedad se debe a la ausencia de validación de autenticación previa al procesamiento de datos en el controlador Geo.
M Crítico vulnerabilidad
27/08/2026
Inyección SQL sin autenticación en Beautiful Taxonomy Filters <= 2.4.6
Se ha identificado una vulnerabilidad crítica de inyección SQL sin autenticación en Beautiful Taxonomy Filters versión 2.4.6 y anteriores, con puntuación CVSS de 9.3. Esta falla permite a atacantes remotos ejecutar comandos SQL arbitrarios contra bases de datos de sitios WordPress afectados, comprometiendo la confidencialidad e integridad de datos. Empresas en LATAM que utilizan este plugin en sitios de comercio electrónico, portales administrativos o plataformas de contenido están expuestas a robo de información sensible y manipulación de registros.
M Crítico vulnerabilidad
27/08/2026
Inyección de objetos PHP sin autenticación en Hash Form <= 1.4.1 (CVE-2026-78292)
Vulnerabilidad crítica (CVSS 9.8) en Hash Form versión 1.4.1 y anteriores permite inyección de objetos PHP sin requerir autenticación. Un atacante remoto puede ejecutar código arbitrario comprometiendo servidores web en empresas mexicanas y latinoamericanas. El riesgo es máximo en entornos de e-commerce, plataformas de gestión y aplicaciones expuestas a internet.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-78274] Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Editor Arbitrary File Upload in Fluent Boards Pro
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-78260] Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Unauthenticated SQL Injection in Epayco
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-59354] In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynami…
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-32479] Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-32566] Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.6…
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-77016] The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user'…
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-59270] Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an a…
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47890] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event…
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47891] A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not corr…
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47884] Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has…
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and ea…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-70419] Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special…
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-81032] NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon star…
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and registers routes for reading and writing gflags alongside status and statistics. Neither the service nor its router carries any authentication, token check or address restriction. The read…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80428] ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel en…
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and its logout-notification handler locates the session to terminate by reading every live row of the session table and passing each row's stored data to a hand-wr…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-54569] SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.…
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many,…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80587] In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some inc…
In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also because in different places, the code doesn't expect some combinations to be present. That's specially true for suboptions that would be present twice, but with different attributes. The new restrictio…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80589] In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer w…
In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for a disk whose probe failed before add_disk(), but it only calls blk_mq_exit_queue(). Nothing there stops q->timeout, and that timer rolls forward: it stays pending until it next expires, not until the last reque…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80585] In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTF…
In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty. mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SY…