Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-106241] Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a re…
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106249] Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a …
Incorrect authorization in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106212] Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacke…
Incorrect authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-102322] Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote at…
Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105797] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. In versions 0.261.003 and 0.261.027, an authorization ordering flaw in POST /api/user/plugins allows an authenticated low-privileged user to omit the top-level MCP type so that _reject_non_admin_mcp_stdio skips inspection before the type is restored from metadata. The stored pe…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-77226] Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web app…
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting only direct members of the camunda-admin group rather than recognizing all configured administrators. An unauthenticated remote attacker can exploit this logic flaw to call the setup user-c…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104978] Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list end…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attack…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104891] mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @in…
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrap…
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta en YesWiki anterior a 4.6.7 permite bypass de filtros en API de triples
YesWiki versiones anteriores a 4.6.7 contiene un bypass de alcance en el filtro vacío de la API de eliminación de triples que permite a usuarios autenticados eliminar o falsificar triples semánticos arbitrarios sin importar propiedad. Un atacante puede enviar un filtro vacío para remover la membresía del grupo de administradores, vaciando el grupo administrativo y causando un bloqueo de autorización en todo el sitio. Este vector afecta directamente la integridad y disponibilidad de plataformas wiki colaborativas usadas en gobiernos, universidades y empresas de LATAM.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad de omisión de autorización en Obot 0.21.1 a 0.24.1 (CVE-2026-103758)
Obot versiones 0.21.1 hasta 0.24.1 contienen una vulnerabilidad de omisión de controles de autorización que permite a usuarios autenticados con rol básico acceder a servidores MCP mediante la ruta /mcp-connect-composite/, no incluida en la lista de denegación. Usuarios con IDs MCP compuestos pueden enviar solicitudes proxy a través de mcpGateway.Proxy para invocar herramientas en servidores restringidos, evadiendo reglas de control de acceso.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost 4.0.0-6.62.x permite acceso no autenticado a contenido restringido
Ghost versiones 4.0.0 a 6.62.x contienen una vulnerabilidad en la API de contenido que permite a visitantes no autenticados acceder a posts protegidos mediante consultas directas a la API, eludiendo restricciones de acceso. Afecta principalmente a plataformas editoriales y SaaS que utilizan Ghost como CMS, especialmente alta en México y LATAM donde proliferan blogs corporativos y medios digitales con contenido de suscripción.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost 5.2.0 a 6.61.x permite inyección de contenido sin autenticación
Ghost versions 5.2.0 hasta anteriores a 6.62.0 contienen una vulnerabilidad que permite a atacantes remotos, sin autenticación, explotar el flujo de Stripe Checkout para adjuntar suscripciones pagas a miembros existentes, modificar nombres de usuarios e inyectar contenido malicioso en newsletters. El contenido inyectado puede ejecutarse como HTML o XSS dependiendo del cliente de correo, afectando principalmente a plataformas de publicación y membership en LATAM que utilizan Ghost para contenido de pago.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103259] n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in…
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103488] In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add t…
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues
M Alto vulnerabilidad
01/10/2026
[CVE-2026-82828] Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unpri…
Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101880] OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the syste…
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55176] Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.…
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the …
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47591] NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unpri…
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47571] NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where …
NVIDIA GPU Display Driver for Windows contains a vulnerability in kernel-mode escape handling where an attacker with local access could bypass an authorization check that is intended to restrict certain operations based on client execution context. A successful exploit of this vulnerability might lead to escalation of privilege, information disclosure, data tampering, denial of service, or code ex…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100277] In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification …
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature