Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84696] Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique comm…
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84423] A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file …
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanat…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-79687] Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unau…
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-18771] Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co…
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82919] A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the func…
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-54598] Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpo…
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against the live SQLite database. This issue has been patched in version 4.9.4.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-75133] Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulner…
Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable dump filename based on the database name, a limited random range, and the current…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-66047] ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code…
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin …
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82693] A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function …
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82694] A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSe…
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82695] A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of th…
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-58574] Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenti…
Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full adminis…
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82641] keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces with…
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en Documenso: carga de PDF sin autenticación en endpoint /api/files/upload-pdf
Documenso versiones anteriores a 2.13.0 permite la carga de archivos PDF sin requerir autenticación en el endpoint /api/files/upload-pdf. Atacantes no autenticados pueden subir PDFs arbitrarios indefinidamente, agotando recursos de almacenamiento y saturando bases de datos con registros huérfanos. Esta vulnerabilidad afecta principalmente a empresas mexicanas y latinoamericanas que utilizan Documenso para gestión de documentos digitales y flujos de firma electrónica.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en KubeEdge CloudCore 1.23.1 permite falsificación de estado de actualización de nodos
KubeEdge CloudCore versiones hasta 1.23.1 acepta reportes de estado de tareas sin autenticación en puerto 10002, permitiendo a atacantes modificar el estado de trabajos de upgrade. Esto compromete la integridad del plano de control en infraestructuras edge/IoT, siendo alta para organizaciones en LATAM con despliegues en manufactura, utilities y telecomunicaciones que dependen de orquestación automática de actualizaciones.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-82452] rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most…
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without providing valid credentials.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82282] Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticat…
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook payload forgery.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82277] Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operatio…
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82266] Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t…
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-78239] Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, …
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.