Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2025-15637] Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
Unauthenticated Local File Inclusion in Shuffle
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-73197] A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by se…
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-73198] A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `…
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-13097] A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri…
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized a…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-11861] A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Dire…
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certifi…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-18917] A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerabil…
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denia…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14948] A low privileged remote attacker can hijack an active administrative session without needing to know…
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-14950] An unauthenticated remote attacker in possession of a valid session identifier is able to continue u…
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14951] An low privileged remote attacker can cause authenticated users to perform unintended actions in the…
An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14952] An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the …
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14947] A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal se…
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14946] A high privileged remote attacker can upload a .php file and then request it directly from /uploads/…
A high privileged remote attacker can upload a .php file and then request it directly from /uploads/.php to achieve arbitrary code execution due to improper file type validation which could result in full system compromise.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-75963] The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up t…
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to …
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-75860] The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica…
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-15049] The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a …
The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does not remove a malformed upload, allowing users with editor-level access to write an arbitrary file (including executable PHP) into a web-accessible directory, which can lead to remote code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76956] In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to ins…
In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-19582] In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could exe…
In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buffer overflow out of bounds write.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76795] A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of th…
A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.0 will fix this issue. The identifier of the patch i…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76783] A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown …
A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76762] A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an …
A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.