Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18620] A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper au…
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to run their containers with elevated privileges, potentially leading to the disclos…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72876] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swa…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an activeOrganizationId ownership check, and getNodeInfo in packages/server/src/services/docker.ts interpolates nodeId into execAsyncRemote, allowing a …
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72863] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() and then proceed without consulting the role/permission model that every tRPC procedure enforces. Any authenticated member, can therefore open an inter…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72737] Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create,…
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs in apps/dokploy/server/api/routers/backup.ts accept a client-controlled destinationId and use the referenced destination without verifying that destination.organizationId equals ctx.session.activeOrganizationId. An authenticated member with backup per…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72734] Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server…
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutation in apps/dokploy/server/api/routers/server.ts accepts a caller-controlled serverId and calls haveActiveServices, findServerById, removeDeploymentsByServerId, and deleteServer without verifying that currentServer.organizationId equals ctx.session.activeOrganizationId. An authenti…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72689] A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allo…
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the …
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72690] An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated …
An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory survey questions into another organizer's events via the POST /event/{event_id}/question/create endpoint. The postCreateEventQuestion method loads the target event without the tenant-isolation scope, enabling cross-tenant writes; the injected question c…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72564] An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated re…
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta de aislamiento en PraisonAI Platform API 0.1.3 y anteriores (CVE-2026-48169)
PraisonAI Platform API versiones anteriores a 0.1.4 presentan dos fallos de autorización que comprometen el aislamiento de workspaces. Usuarios autenticados pueden leer, modificar y eliminar recursos en cualquier workspace modificando UUIDs en solicitudes API, afectando altas equipos de IA multi-agente en organizaciones de LATAM que usan esta plataforma en producción.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67622] Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assis…
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector s…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-45414] Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2,…
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19111] Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools …
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter. To remediate this issue, users should upgrade to version 0.8.3.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18258] Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoint…
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65523] Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contra…
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad de Autorización en Crater: Acceso no autorizado a notas sin validación de empresa
Crater presenta una falla alta en su NotePolicy que valida permisos genéricos (manage-all-notes/view-all-notes) sin verificar la propiedad de la empresa asociada, a diferencia de InvoicePolicy. Los controladores NotesController permiten acciones show(), update() y destroy() sin pasar el modelo Note afectado, exponiendo notas de otras organizaciones. Este defecto afecta a empresas en LATAM que usan Crater para gestión de facturas y documentación.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-55739] Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both …
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers() method are similarly unscoped (self…
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-2346] Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App a…
Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026.
M Alto vulnerabilidad
02/08/2026
[CVE-2025-71400] better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability …
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the delete-passkey endpoint with enumerated passkey IDs to remove other users' passkeys.
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica de bypass de autorización en ArcadeDB anterior a v26.7.2
ArcadeDB versiones anteriores a 26.7.2 contienen una vulnerabilidad de bypass de autorización en manejadores HTTP que afecta endpoints de series de tiempo, batch, Prometheus y Grafana. Los atacantes pueden acceder y modificar bases de datos sin permisos autorizados al invocar directamente estos endpoints con parámetros arbitrarios de base de datos. Esta falla impacta empresas en LATAM que usan ArcadeDB para almacenamiento de datos críticos o monitoreo.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad de omisión de autorización en @better-auth/stripe afecta gestión de suscripciones
Las versiones 1.4.11 a 1.6.20 y 1.7.0-beta.0 a 1.7.0-beta.9 de @better-auth/stripe contienen una falla de validación que permite eludir controles de autorización en acciones de suscripción organizacional. Un atacante puede manipular parámetros de ID de organización para acceder o modificar suscripciones de terceros. Afecta principalmente a plataformas SaaS y aplicaciones con modelos multi-tenancy que utilicen esta librería para autenticación con Stripe.