Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
17/08/2026
[CVE-2026-34789] FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/Prope…
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd document, which executes module-level Python code, and the legacy pickle branch also imp…
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-19478] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19980] A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE930…
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated re…
M Alto vulnerabilidad
16/08/2026
Inyección de código en plugin WCPOS para WooCommerce afecta tiendas en línea
El plugin WCPOS (Point of Sale) para WooCommerce en WordPress contiene una vulnerabilidad alta de inyección de código en el motor de plantillas 'thermal' hasta la versión 1.9.14. Atacantes autenticados pueden ejecutar código PHP arbitrario a través del renderizador de recibos, comprometiendo datos de ventas y clientes en tiendas electrónicas de México y Latinoamérica que utilizan este sistema POS.
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-73678] MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution …
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-73679] ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module th…
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before passing it to eval() in the renderWithPhp() method, bypassing HTML Purifier saniti…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-46439] compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 a…
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads i…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19768] Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow…
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta de ejecución remota de código en Grav CMS 2.0.12 y anteriores
Grav CMS versiones anteriores a 2.0.13 contiene una vulnerabilidad de ejecución remota de código (RCE) en la validación de configuración del plugin Flex Objects. Un atacante autenticado puede eludir la validación de nombres mediante notación de arreglos y cargar un archivo ZIP malicioso con código PHP, escribiendo archivos ejecutables en el directorio raíz web. Esta vulnerabilidad afecta directamente a portales, sitios dinámicos y plataformas de gestión de contenidos en organizaciones de México y Latinoamérica que utilizan esta CMS.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73649] Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, t…
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73505] Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 2…
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name containing a Go template expression could execute arbitrary operating system commands as the current u…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-67986] amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code …
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application pa…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-61962] Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-27544] Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13094] IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on …
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73268] A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant …
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73299] Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the T…
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-65941] In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network a…
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73291] Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to v…
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId route, allowing a malicious or compromised Jellyfin or Emby server, or a man-in-the-middle attacker…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-16051] The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages inst…
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to install and execute arbitrary code (remote code execution).