Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Dify" — 77 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-104076] TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing auth…
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration via unprotected REST API endpoints on port 8288. Attackers can send unauthenticated GET requests to disclose network configuration, firmware details, and cloud s…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-107206] LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP …
LMCache through 0.5.5 contains a missing authentication vulnerability in the multiprocess mode HTTP server that allows remote unauthenticated attackers to access management endpoints listening on all interfaces by default. Attackers can read environment credentials via GET /env and configuration via GET /config, clear caches, delete cache objects, and modify tenant quotas to evict other tenants' c…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-79805] An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploit…
An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-104070] The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows …
The Crayons plugin for SPIP before 3.5.0 contains a missing authorization vulnerability that allows unauthenticated attackers to modify arbitrary editable object fields by omitting the secu_ anti-forgery parameter in crayons_store.php, causing the authorization dispatcher to resolve an unconditionally-true handler instead of the proper modification check. Attackers can chain this flaw to write a m…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-94293] An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH req…
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-93697] There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Account…
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-82824] Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that …
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102106] Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administr…
Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and…
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-96587] The Viidure Android application embeds permanent, plaintext cloud storage credentials within its com…
The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.
M Crítico vulnerabilidad
29/09/2026
[CVE-2023-54400] Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that al…
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with…
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de autenticación en Hitachi Energy RTU500 permite carga de firmware no autorizada
Se ha identificado una vulnerabilidad de omisión de autenticación (CVE-2026-8065, CVSS 9.1) en el endpoint de actualización de firmware de Hitachi Energy RTU500 que permite a atacantes no autenticados cargar firmware malicioso mediante solicitudes POST modificadas. La explotación exitosa podría comprometer la funcionalidad operativa, integridad y disponibilidad del dispositivo, afectando principalmente infraestructuras críticas de energía, agua y telecomunicaciones en LATAM que dependen de estos controladores RTU.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-49994] Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Blue…
Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify applica…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82377] Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete…
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting ar…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-86708] ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of …
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17472] IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unau…
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-95675] D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution …
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management interface without valid credentials. Attackers can fully compromise the device to persistently modify its configuration and use it as a pivot point into the loc…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-77240] WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_updat…
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify their own account_role and account_id, allowing a viewer to self-promote or move into another tenant and then access or modify tenant resources. Separately, match_ai_knowledge_fts and mat…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92953] vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes fr…
vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing host-created typed arrays to observe attacker-controlled properties after VM.run() returns.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20284] A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to co…
A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the unde…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-14349] The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to auth…
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the email address of arbitrary user accounts, including administrators, which …