Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
04/06/2026
[CVE-2025-67447] The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerabl…
The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user input in the IP address field before passing it to the system's ping command. An attacker can inject arbitrary OS commands, which will be executed with the privileges of the web server.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50076] Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK…
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes thi…
M Crítico vulnerabilidad
04/06/2026
[CVE-2025-67446] Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and …
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and gain unauthorized access to admin functionalities.
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-43986] Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.1…
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-side image fetch logic used by authenticated image proxying. A low-privilege guest user can seed a malicious external image URL into this lookup table…
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-36182] GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, po…
GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-35904] Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07…
Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via sending a crafted request to a vulnerable CGI component.
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-35905] T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to conta…
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-35906] An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allow…
An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HTTP query string.
P Crítico vulnerabilidad
04/06/2026
[CVE-2026-8037] OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an u…
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
M Crítico vulnerabilidad
04/06/2026
[CVE-2019-25738] WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allow…
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option to enable user registration and set the default role to administrator, enabling a…
M Crítico vulnerabilidad
04/06/2026
[CVE-2019-25741] Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerab…
Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data that triggers the vulnerability when imported and executed, enabling reverse shell execution with user privileges.
M Crítico vulnerabilidad
04/06/2026
[CVE-2019-25727] WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows …
WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter to read arbitrary files like wp-config.php accessible to the web server.
M Crítico vulnerabilidad
04/06/2026
[CVE-2019-25729] PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated a…
PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection payloads like shell_exec() to execute system commands and retrieve sensitive information from the server.
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-4104] Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Auto…
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50225] The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious…
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50214] The /v1/Plan service relies entirely on a shared global API token for full administrative management…
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50208] High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-cod…
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50211] Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail buil…
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49191] The production build of the M3WebServer hard-codes its backend API keys, which can be easily interce…
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49188] The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), …
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.