Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1797
Esta semana
RSS
M Alto vulnerabilidad
18/06/2026
[CVE-2026-56075] PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI mo…
PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable. Authenticated attackers can instruct the LLM agent to execute arbitrary shell commands via subprocess.run with shell=True, bypassing the manual approval gate and insufficient…
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-54803] Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.
Subscriber Privilege Escalation in SMS Alert Order Notifications
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-48781] Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration cal…
Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob into a session-shape JWT using the application's JWT_SECRET, and the auth middleware trusted every claim in that JWT without re-resolving the user from the database. Any authenticated Postiz user could forge a SUPERADMIN session and impersonate arbitrary…
A Crítico vulnerabilidad
17/06/2026
[CVE-2026-32966] DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apa…
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
A Crítico vulnerabilidad
17/06/2026
[CVE-2026-32967] Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. T…
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
O Alto vulnerabilidad
16/06/2026
[CVE-2026-53853] OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that …
OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly invoking allowlisted executables with unrestricted arguments, potentially enabling unauthorized file access, network access, or…
O Alto vulnerabilidad
16/06/2026
[CVE-2026-53855] OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operato…
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools with shell positional arguments to place inline-eval content in shell carriers outside intended allowlist rules, enabling execution of unapproved shell-provided content.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-47777] Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a m…
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and faking consent. An attacker could forge the FeatureAuthorization object that is used to verify consent to be featured in a Collection and thus make it appe…
M Alto vulnerabilidad
15/06/2026
[CVE-2016-20075] WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows…
WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file field and access them via the upcp-product-file-uploads directory to execute arb…
O Alto vulnerabilidad
12/06/2026
[CVE-2026-53834] OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash…
OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access control policies are applied, potentially triggering command handling from blocked senders depending on operator configuration.
O Alto vulnerabilidad
12/06/2026
[CVE-2026-53828] OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling t…
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to bypass the configured owner-command access control, potentially executing privileged commands from unauthorized users.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47120] Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From…
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). This issue has been patched in version 2.0.8.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-46717] Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From…
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, nezha's dashboard supports two user roles: RoleAdmin (Role==0) and RoleMember (Role==1). The notification routes POST /api/v1/notification and PATCH /api/v1/notification/:id are wired through commonHandler rather than adminHandler — so a RoleMember user can ca…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-7387] Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mat…
Mattermost versions 11.6.x
T Alto vulnerabilidad
12/06/2026
[CVE-2026-45831] The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaD…
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
N Alto vulnerabilidad
12/06/2026
[CVE-2026-53721] Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 a…
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.
O Alto vulnerabilidad
11/06/2026
[CVE-2026-53807] OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive call…
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.
M Alto vulnerabilidad
11/06/2026
[CVE-2026-46519] mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to…
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer (too…
M Alto vulnerabilidad
10/06/2026
[CVE-2026-53738] Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in t…
Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite plugin settings via the f parameter, bypassing per-function capability checks.
P Alto vulnerabilidad
10/06/2026
[CVE-2026-0272] A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated …
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management inte…