Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81786] Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions…
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite escalada de privilegios
La cámara IP GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a usuarios invitados sobrescribir la configuración del dispositivo y reemplazar la contraseña del administrador a través del servicio SSVR. Esta falla afecta directamente a sistemas de videovigilancia desplegados en México y Latinoamérica, poniendo en riesgo el acceso no autorizado a infraestructura alta de seguridad física.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-78361] The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform …
The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to destroy site and access control configuration, deactivate every installed zipMoney…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-77770] The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOran…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-14873] The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeo…
The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79324] Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/mo…
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86762] Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware gro…
Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a result, although a deactivated account is correctly refused at web login, its existing API token continues to authenticate and to grant read and write access to the REST API (assets, …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86759] Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any a…
Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87036] Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87072] Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87569] Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker lev…
Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87537] Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacke…
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87487] Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacke…
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86819] Waves Central for macOS contains a local privilege escalation in the privileged helper service. The …
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier and Team ID). A local, authenticated user can execute code within the vendor-signed…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-84869] A condition in the ScreenConnect client may allow files to be transferred and executed through an ac…
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-83941] Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network…
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83942] Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73014] Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privil…
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69724] Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code o…
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69641] Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileg…
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.