Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19908] PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows networ…
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to a…
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-50027] mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes…
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote attacker can upload arbitrary content into the memory store (write), retrieve stored document content (…
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-73849] Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r…
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email values to cause file_put_contents('config.php', $config) t…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-73673] Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability tha…
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentica…
M Crítico vulnerabilidad
14/08/2026
Vulnerabilidad crítica en getgrav/grav-plugin-api: escalada de privilegios en desactivación de 2FA
El paquete Composer getgrav/grav-plugin-api versiones
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73842] OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and …
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73843] OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, i…
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods i…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73666] OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo …
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This i…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72776] AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that al…
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-14525] IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Serve…
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49827] WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1…
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chai…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59506] CWE-306: Missing Authentication for Critical Function
CWE-306: Missing Authentication for Critical Function
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49819] UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentica…
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers > 0` count check — a conditio…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73296] Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t…
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_t…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-65941] In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network a…
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad alta de autenticación faltante en sistema POS de FitSoft (CVE-2026-19426)
El sistema POS desarrollado por FitSoft contiene una vulnerabilidad de autenticación ausente que permite a atacantes remotos no autenticados acceder y operar directamente el sistema. Este defecto afecta principalmente a comercios minoristas, restaurantes y negocios de fitness en LATAM que utilizan esta solución. Con puntuación CVSS 8.2, representa un riesgo alta para la integridad de transacciones y datos de clientes.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73246] Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/s…
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers while the main API o…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66875] In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attac…
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73222] Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the…
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute endpoint passes the prompt request-body field to executeLocalTask(), and POST /api/i…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-64921] Missing authentication for critical function in Microsoft Office SharePoint allows an authorized att…
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.