Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69641] Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileg…
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69553] Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a …
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69465] Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code o…
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69377] Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to ele…
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69380] Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileg…
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-47625] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse miss…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86665] A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the functio…
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-18851] Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8…
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-12645] A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authe…
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-12646] A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authe…
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-12647] A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authe…
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Alto vulnerabilidad
08/09/2026
Plugin Event Tickets and Registration para WordPress vulnerable a modificación no autorizada de credenciales Stripe
El plugin Event Tickets and Registration en WordPress (versiones hasta 5.27.4) presenta una falla alta de validación de permisos en el endpoint de retorno OAuth de Stripe, permitiendo que atacantes no autenticados sobrescriban credenciales del comerciante (tokens de acceso, claves públicas e ID de cuenta). Esto afecta directamente a tiendas en línea, plataformas de eventos y sitios de registro en México y LATAM que procesan pagos a través de Stripe.
M Alto vulnerabilidad
08/09/2026
Plugin EDD Product Catalog Feed para WordPress vulnerable a eliminación no autorizada de datos
El plugin EDD Product Catalog Feed by PixelYourSite en WordPress (versiones hasta 1.0.2) contiene una falta de validación de permisos en la función wpeddpcf_delete_feed, permitiendo a usuarios autenticados con acceso de suscriptor o superior eliminar valores de opciones arbitrarias. Esto puede provocar denegación de servicio y corrupción de datos altas en tiendas en línea y plataformas de comercio electrónico en LATAM.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81781] Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting In…
Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81790] Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez…
Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86438] Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire a…
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86494] In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links…
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86479] In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allow…
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-61410] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system…
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta en tema Nokri Job Board para WordPress permite escalada de privilegios
El tema WordPress Nokri – Job Board (versiones hasta 1.6.4) contiene una falta de validación de permisos en la función 'nokri_account_member_permissions', permitiendo a usuarios autenticados con acceso de Suscriptor crear nuevos usuarios con permisos de empleador. Esta vulnerabilidad afecta especialmente a plataformas de empleo y bolsas de trabajo en LATAM que utilizan este tema para gestionar portales de reclutamiento.