Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85213] Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints…
Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84989] ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, …
ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` — perform no authorization check at all. Any authenticated user, including a non-administrator ("unprivileged") account, can delete or rename any tag in the …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-53635] Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commi…
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated user — including a learner account with zero course roles — can issue a single P…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-45730] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization checks on write paths (PUT /api/projects/{id}, DELETE /api/projects) and modify or delete any project along with all its ass…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18058] The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired wit…
The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.
M Alto vulnerabilidad
02/09/2026
[CVE-2025-15485] The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its RES…
The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de autorización en Craft CMS 5.0.0-RC1 a 5.10.10 permite eliminación no autorizada
Craft CMS versiones desde 5.0.0-RC1 hasta 5.10.10 presentan un fallo en la validación de autorización independiente en ElementsController::actionDeleteForSite(). El método verifica permisos únicamente contra el borrador provisional del usuario, permitiendo que la eliminación se propague al elemento canónico sin re-validación. Esto expone plataformas de contenido en LATAM a eliminación no autorizada de datos altas con CVSS 7.1.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de autorización en Craft CMS 5.0.0-RC1 a 5.10.10 permite reemplazo no autorizado de activos
Craft CMS versiones 5.0.0-RC1 hasta 5.10.10 contienen un fallo de autorización en AssetsController::actionReplaceFile que permite a usuarios autenticados con permisos limitados reemplazar archivos sin validación de permisos. El defecto ocurre cuando se omite el parámetro assetId, resolviendo el activo destino por carpeta y nombre de archivo después de las verificaciones de permisos. Empresas en LATAM con portales de contenido, sitios de agencias digitales o plataformas de gestión de medios basadas en Craft CMS están potencialmente expuestas.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta en Craft CMS anterior a 5.10.11 permite escalada de privilegios
Craft CMS versiones anteriores a 5.10.11 no validan correctamente el estado de administrador en el endpoint actionGetPasswordResetUrl, permitiendo a usuarios no-administradores con permiso administrateUsers generar URLs de reseteo de contraseña para cuentas administrativas. Un atacante puede crear URLs válidas de reinicio y establecer nuevas contraseñas sin validación adicional del llamador, comprometiendo completamente la seguridad de sistemas CMS en producción.
M Alto vulnerabilidad
02/09/2026
Craft CMS: falla de autorización en gestión de activos permite eliminación no autorizada
Craft CMS versiones anteriores a 5.10.11 presentan verificación insuficiente de permisos en el endpoint assets/move-asset cuando se activa el parámetro force=1. Usuarios autenticados sin permisos en activos pueden mover archivos a carpetas de otros usuarios y forzar eliminación de conflictos, comprometiendo la integridad de contenido. Afecta principalmente a agencias digitales, portales de contenido y plataformas de medios en LATAM que dependen de Craft CMS para gestión colaborativa.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-14357] The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and in…
The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing nonce validation in the DPDEV_install_themes_func() function registered on the wp_ajax_DPDEV_install_themes action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary t…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84715] FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSu…
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82882] Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webho…
Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81892] EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 an…
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81296] Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-79748] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is requi…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79744] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no authorization check. It is protected only by the app-wide authentication middleware and a rate limiter — it never inspects req.user.…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79745] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in prompt and resource controllers perform no role checking. The mutating POST/PUT /api/prompts* and POST/PUT /api/resources* routes are attached to the authenticated router with no admin gate, and the ha…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-77966] The affected Ebyte product does not provide separation between limited and administrative managem…
The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-19616] Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionalit…
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2.