Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-76943] Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allo…
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-16639] Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalizatio…
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-63587] The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the …
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliber…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78259] Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages
M Crítico vulnerabilidad
20/08/2026
Autenticación rota en User Registration & Membership Pro <= 5.4.5 (CVE-2026-74001)
Se ha identificado una vulnerabilidad crítica de autenticación sin validación en User Registration & Membership Pro versión 5.4.5 y anteriores, permitiendo a atacantes acceder a funciones sensibles sin credenciales válidas. Afecta principalmente a sitios WordPress en México y LATAM que utilizan este plugin para gestión de usuarios. El CVSS de 9.8 indica riesgo severo para confidencialidad e integridad de datos de membresía.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-66677] Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Subscriber Broken Authentication in Leyka
M Alto vulnerabilidad
18/08/2026
[CVE-2026-50191] 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerabl…
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-24185] NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configura…
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could inadvertently enable an alternative authentication path. If best practices for replacing the default password as recommended by NVIDIA are not followed, this alternative authentication path might lead to unauthorized access.…
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-73381] Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Broken Authentication in Popup by Supsystic
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73396] Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Subscriber Broken Authentication in MWB HubSpot for WooCommerce
M Alto vulnerabilidad
18/08/2026
[CVE-2026-32481] Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
Unauthenticated Broken Authentication in Ezoic
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75627] Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unaut…
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-75045] In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker…
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73188] Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
Unauthenticated Sensitive Data Exposure in KiviCare
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66465] Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66453] Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Salon booking system
M Alto vulnerabilidad
12/08/2026
[CVE-2026-70468] A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.…
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72691] An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unaut…
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65542] Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
Unauthenticated Broken Authentication in Super Socializer
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-24254] NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attack…
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.