Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1797
Esta semana
RSS
M Alto vulnerabilidad
16/07/2026
[CVE-2026-57206] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/`, `POST /api/admin/plugins/repair/`, and `POST /…
N Crítico vulnerabilidad
15/07/2026
[CVE-2026-54052] n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, a…
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled through ENABLE_MULTI_TENANT=true, n8n-mcp's local workflow version history backups were not isolated per tenant, allowing an authenticated tenant to read workflow version snapshots belonging to other tenants and delete or destro…
L Alto vulnerabilidad
15/07/2026
[CVE-2026-52870] The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MC…
The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results fro…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-59255] BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in…
BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the global graph schema. Attackers with valid session tokens can create, update, or delete custom node types affecting all users and tenants by invoking unprotected POST, PUT, and DELETE operations on the custom-nodes endpo…
B Alto vulnerabilidad
15/07/2026
[CVE-2026-53514] Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1…
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin's acceptInvitation, rejectInvitation, getInvitation, and listUserInvitations recipient endpoints use session.user.email and an invita…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-14251] A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate reso…
A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objects. A namespace-scoped Argo CD instance can trigger deletion of a ClusterRole owned by a cluster-scoped Argo CD instance by crafting a name collision, resulting in a denial of service.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15752] A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f92…
A vulnerability was found in zhinianboke xianyu-auto-reply up to dcb445ad97816ad65299a7580ee0c8c8f929da84. Affected is an unknown function of the file /api/v1/users/ of the component Backend User Endpoint. Performing a manipulation results in missing authorization. The attack may be initiated remotely. The exploit has been made public and could be used. This product uses a rolling release model to…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-53633] Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vite…
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP Page.setDownloadBehavior and Runtime.evaluate to overwrite vite.config.ts and execute attacker…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55052] Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privil…
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
13/07/2026
[CVE-2026-62328] 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that …
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated request logs and retrieve complete AI conversation histories including system prompts, user messages, assistant responses, tool calls, and user email addresses by…
O Alto vulnerabilidad
13/07/2026
[CVE-2026-62191] OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message …
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable.
O Alto vulnerabilidad
13/07/2026
[CVE-2026-62194] OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin i…
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable.
O Alto vulnerabilidad
13/07/2026
[CVE-2026-62186] OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible…
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin authorization policies and execute restricted operations.
M Alto vulnerabilidad
13/07/2026
[CVE-2026-58410] ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authoriza…
ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated non-admin user with EditSelf access can supply another family’s `familyId` and access records outside their own family scope. The backend trusts the attacker-contr…
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57740] Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymail…
Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57727] Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured …
Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57729] Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Con…
Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57705] Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorre…
Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57405] Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly C…
Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57378] Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting In…
Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through