Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
CVE-2026-86292: Autenticación ausente en SourceCodester Simple Traffic Offense System 1.0
Se detectó una vulnerabilidad de autenticación faltante en SourceCodester Simple Traffic Offense System 1.0 en el archivo saveuser.php (componente User Creation). Un atacante remoto puede manipular el parámetro position para crear usuarios sin credenciales válidas, comprometiendo la integridad de sistemas de gestión de infracciones de tránsito. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo alto para municipalidades y autoridades viales en LATAM que usan esta plataforma.
M Alto vulnerabilidad
06/09/2026
[CVE-2026-86259] OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowin…
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en Bifrost HTTP transport permite ejecución de código remoto sin autenticación
Bifrost HTTP transport anterior a versión 2.0.0 permite a atacantes no autenticados cargar y ejecutar plugins maliciosos a través de POST /api/plugins cuando la autenticación de gestión está deshabilitada (configuración por defecto). El cargador de objetos compartidos descarga archivos desde URLs HTTP y los ejecuta como librerías dinámicas en Go, comprometiendo completamente servidores en infraestructuras altas de LATAM. Afecta especialmente a plataformas de integración y orquestación de datos sin hardening de seguridad.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de autenticación en Lara Dashboard anterior a v1.3.0
Lara Dashboard versiones anteriores a 1.3.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en la ruta screenshot-login que permite a atacantes no autenticados acceder como cualquier usuario registrado mediante su correo electrónico cuando APP_ENV no está configurado en producción. Explotando el endpoint GET /screenshot-login/{email}, los atacantes obtienen sesiones completamente autenticadas con acceso a administración de usuarios, configuraciones y datos sensibles. Esta falla afecta principalmente a instancias de desarrollo y staging expuestas en entornos LATAM.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica en Cua computer-server permite ejecución remota de comandos sin autenticación
Cua computer-server versiones anteriores a 0.3.42 omiten validación de autenticación cuando la variable de entorno CONTAINER_NAME no está configurada, exponiendo el puerto TCP 8000 a ataques no autenticados. Los atacantes pueden ejecutar comandos arbitrarios, acceder a sistemas de archivos y obtener shells interactivas en servidores empresariales en México y LATAM que utilicen esta versión vulnerable.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de ejecución remota sin autenticación en AutoAgent (CVE-2026-86124)
AutoAgent contiene una vulnerabilidad de ejecución remota de código sin autenticación en su servidor TCP que se vincula a todas las interfaces de red, permitiendo a atacantes ejecutar comandos bash arbitrarios como root. Los atacantes pueden conectarse al puerto expuesto y acceder a directorios del host montados en contenedores, comprometiendo completamente la confidencialidad, integridad y disponibilidad de la infraestructura. Esta vulnerabilidad afecta servidores en entornos containerizados comunes en empresas de LATAM.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85702] A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca92…
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-9317] Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that a…
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85695] FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allow…
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85688] TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the …
TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85671] QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_ba…
QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclos…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85667] xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints…
xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85663] Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods th…
Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85424] MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated cl…
MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85428] MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB…
MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-70352] Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to…
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Joro framework: exposición de API local sin autenticación
Joro, un framework de pruebas web, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.1 que expone una API local sin autenticación en 127.0.0.1:9090 con política CORS permisiva. Un atacante puede ejecutar JavaScript malicioso desde cualquier sitio visitado para cargar plugins nativos y comprometer completamente el sistema. Esta exposición afecta principalmente a equipos de seguridad y desarrolladores que utilizan Joro para análisis de aplicaciones web en infraestructuras empresariales de LATAM.
M Alto vulnerabilidad
02/09/2026
[CVE-2024-35585] Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84485] APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authe…
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84700] PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the cl…
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates …