Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-77903] Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate …
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86039] libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @lib…
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerRecord.peerId in the signed payload to equal the signer peer ID derived by RecordEnvelope.openAndCertify. The expectedPeer option checks only the envelope signer, a…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86863] pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web se…
pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back to reading the same name directly from the inbound HTTP request headers via requ…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-62108] Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
Unauthenticated Broken Authentication in Headless Single Sign On
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-76423] A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remot…
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exp…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92395] @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted re…
@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 addres…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-89022] BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login impleme…
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social provider using a user ID that matches an account linked to a different social provi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-90711] proxy-addr is a Node.js module that determines a request's client address behind trusted reverse pro…
proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the correct ::ffff:10.0.0.0/104, is accepted without error but trusts every IPv4 address on the internet…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-87785] Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS setti…
Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-63427] An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a loca…
An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-82563] An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emula…
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62759] Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spo…
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-86478] In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpde…
In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85432] MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowi…
MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source a…
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en autenticación FIDO2 permite suplantación de identidad en despliegues locales
Una vulnerabilidad de puntuación CVSS 9.8 en sistemas FIDO2 permite a atacantes registrar credenciales maliciosas contra cuentas objetivo y autenticarse como el usuario legítimo. El riesgo afecta únicamente despliegues on-premises. Empresas en LATAM que implementen autenticación FIDO2 en infraestructura interna deben evaluar inmediatamente su exposición, especialmente en sectores financiero, gubernamental y de telecomunicaciones.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-14199] Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syn…
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while th…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84479] WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely o…
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84476] WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers…
WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-58575] Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attack…
Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82228] Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.
Unauthenticated Bypass Vulnerability in SiteGround Security