Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1805
Esta semana
RSS
M Medio vulnerabilidad
06/08/2026
CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad XSS almacenado alta en plugin TranslatePress para WordPress (CVE-2026-18510)
El plugin TranslatePress de WordPress presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en versiones hasta 3.2.6 que permite a atacantes sin autenticación inyectar código malicioso a través de comentarios con marcadores gettext codificados. La falta de sanitización de entrada y escapado de salida afecta directamente a sitios web multilingües en México y LATAM que dependen de este plugin para traducción de contenidos, comprometiendo la integridad y seguridad de visitantes y datos.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16268] The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing r…
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16734] The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the call…
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to change the amount of a payment intent that the Stripe Payment Forms by WP Full Pay …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18050] The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST r…
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, s…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-16054] The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not preven…
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13153] The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its…
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13154] The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-suppl…
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-14829] The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin throug…
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPres…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-12713] The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a para…
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de SSRF en JeecgBoot hasta versión 3.9.2
Se identificó una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en JeecgBoot versiones hasta 3.9.2, específicamente en el componente Anonymous Chat Attachment Parser (/airag/chat/send). El defecto permite a atacantes remotos ejecutar solicitudes HTTP arbitrarias desde el servidor afectado, comprometiendo sistemas internos y datos sensibles. La vulnerabilidad tiene código de explotación público disponible, aumentando significativamente el riesgo para empresas LATAM que usan esta plataforma en producción.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de elusión de autenticación en plugin WPMU DEV Dashboard para WordPress
El plugin WPMU DEV Dashboard para WordPress (versiones hasta 5.0.0) contiene una vulnerabilidad de elusión de autenticación que afecta sitios no conectados al WPMU DEV Hub. La clave API del sitio permanece vacía en la configuración predeterminada, permitiendo falsificar firmas de solicitud WDP-AUTH. Esto expone a empresas mexicanas y latinoamericanas con sitios WordPress multisite a acceso no autorizado a funcionalidades administrativas altas.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18325] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16636] The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Pr…
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-15991] The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f…
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18991] A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknow…
A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report b…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18990] A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file…
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18973] A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is …
A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-67871] Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of …
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server
M Alto vulnerabilidad
06/08/2026
[CVE-2026-67872] An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event…
An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling