Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-104075] TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authenticat…
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript val…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-62101] Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Unauthenticated Broken Authentication in EduAdmin Booking
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27546] An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function…
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-62916] Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorize…
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76943] Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allo…
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-16639] Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalizatio…
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
M Crítico vulnerabilidad
20/08/2026
Autenticación rota en User Registration & Membership Pro <= 5.4.5 (CVE-2026-74001)
Se ha identificado una vulnerabilidad crítica de autenticación sin validación en User Registration & Membership Pro versión 5.4.5 y anteriores, permitiendo a atacantes acceder a funciones sensibles sin credenciales válidas. Afecta principalmente a sitios WordPress en México y LATAM que utilizan este plugin para gestión de usuarios. El CVSS de 9.8 indica riesgo severo para confidencialidad e integridad de datos de membresía.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-73381] Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Broken Authentication in Popup by Supsystic
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75627] Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unaut…
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-75045] In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker…
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66465] Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66453] Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Salon booking system
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-24254] NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attack…
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Crítico vulnerabilidad
28/07/2026
[CVE-2026-15014] The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for …
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistration()` function using a phone-unbound `$_SESSION['sa_mobile_verified']` boolean flag as the sole gate before…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-61884] The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side vali…
The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, dev…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-57807] Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Softwa…
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password Recovery Exploitation. This issue affects OAuth Single Sign On - SSO (OAuth Client): from n/a through 38.5.8.
M Crítico vulnerabilidad
06/07/2026
[CVE-2026-5268] An authentication bypass vulnerability exists in the default SFTP server component utilized across t…
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-58172] Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability tha…
Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requests. The WebSocket upgrade pipeline branch configured via MapWhen in OcelotPipelineExtensions.cs omits SecurityMiddleware, causing requests from blocked IP addresses to be proxied to downstream servi…
K Crítico vulnerabilidad
26/06/2026
[CVE-2026-53576] Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authe…
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addresses its resources by URL path segments that the caller chooses (/api/v1/{tenant}/flows/{namespace},…
T Crítico vulnerabilidad
23/06/2026
[CVE-2026-48491] Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity…
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientC…