Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72537] A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta…
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attac…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72886] Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.c…
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in the alternative branch, allowing a member with access to one application to attach its applicationId to a dokploy-server sc…
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72863] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() and then proceed without consulting the role/permission model that every tRPC procedure enforces. Any authenticated member, can therefore open an inter…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19381] A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacte…
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted e…
M Crítico vulnerabilidad
08/08/2026
Plugin AI Copilot – Content Generator para WordPress vulnerable a bypass de autorización
El plugin AI Copilot – Content Generator en WordPress (versiones hasta 1.5.6) presenta una vulnerabilidad crítica de bypass de autorización (CVSS 9.8) que permite a atacantes no autenticados crear cuentas de administrador y comprometer completamente el sitio web. Esta vulnerabilidad afecta especialmente a empresas en LATAM que utilizan WordPress para presencia digital y e-commerce.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-64637] Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated re…
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-15215] The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capabilit…
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) t…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad de escalada de privilegios en PowerISO 9.3.0.0 (CVE-2026-19189)
Se ha descubierto una flaw de seguridad en PowerISO versión 9.3.0.0 que afecta el controlador de kernel scdemu.sys, permitiendo escalada impropia de privilegios. El exploit está público y requiere acceso local a la máquina. Empresas en LATAM que usen esta herramienta para virtualización o gestión de imágenes ISO deben evaluar el riesgo inmediato en estaciones de trabajo y servidores, especialmente en entornos donde usuarios estándar comparten equipos.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48086] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL…
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica en productos WSO2: escalación de privilegios mediante tokens insuficientemente restringidos (CVE-2026-1728)
Productos WSO2 emiten tokens a usuarios con pocos privilegios sin restricciones suficientes, permitiendo acceso a APIs REST administrativas. Un atacante con cuenta de bajo privilegio puede ejecutar operaciones administrativas, comprometiendo completamente las cuentas administrativas. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan WSO2 para gestión de identidades y APIs en entornos de producción.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9193] An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Serve…
An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7327] An improper privilege management vulnerability in the REST API document processing pipeline of Progr…
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-7329] An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces o…
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-8709] An improper privilege management vulnerability in the REST API document patch operation of Progress …
An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18322] The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versi…
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18606] A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is…
A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe Handler. Executing a manipulation of the argument lpThreadParameter can lead to improper privilege management. The attack requires local access. The exploit has be…
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-16534] The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's…
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
M Alto vulnerabilidad
02/08/2026
[CVE-2026-67356] ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with Hos…
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users, escalating privileges beyond their authorization level.
M Alto vulnerabilidad
01/08/2026
[CVE-2026-16635] The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, a…
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed->user_role_field_id]`) directly into `WP_User::set_role()` without any allowlist validation, capability comparison, or permission check to constrain whic…
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15414] The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in vers…
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged roles — the only validations applied, `sanitize_key()` and `wp_roles()->is_role()`, both accept `'ad…