Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2119 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta en CAPEv2: falta de validación de propiedad en API REST
CAPEv2 hasta el commit 471ee4b presenta una falla de control de acceso en sus endpoints REST que permite a usuarios autenticados leer y eliminar análisis de malware enviados por otros usuarios. Los atacantes pueden enumerar todas las tareas del sistema y borrar análisis arbitrarios sin verificación de propiedad, comprometiendo la integridad de investigaciones de seguridad en laboratorios de análisis dinámico.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta en Open Notebook anterior a 1.11.0 permite SSRF autenticado
Open Notebook versiones anteriores a 1.11.0 contiene una falla de validación en el parámetro URL del endpoint POST /api/sources que permite a usuarios autenticados ejecutar solicitudes HTTP arbitrarias desde el servidor hacia servicios internos, metadatos en la nube y servicios locales. Esto expone credenciales de infraestructura en cloud (AWS, Azure, GCP) y datos sensibles de redes corporativas internas en organizaciones LATAM que utilizan esta plataforma.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta en LangBot: claves de recuperación débiles permiten acceso no autorizado
LangBot versiones anteriores a 4.10.11 genera claves de recuperación de contraseña con solo 24 bits de entropía sin protección contra ataques de fuerza bruta. Un atacante remoto que conozca el correo del administrador puede comprometer la cuenta mediante solicitudes concurrentes al endpoint de restablecimiento de contraseña sin autenticación. Esto afecta directamente la seguridad perimetral de sistemas altas en empresas latinoamericanas que utilizan este software.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-89080] The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated reques…
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90678] An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitatio…
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic must reach a backend over HTTP/1.1 using chunked transfer coding on a reused connection. Under those conditions, when an HTTP/3 request carries no Content-Length …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90668] The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP reque…
The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90651] Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify u…
Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts an…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-85681] The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one …
The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled …
M Alto vulnerabilidad
12/09/2026
[CVE-2026-77752] The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user req…
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promo…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81429] The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF c…
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-77005] The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file pa…
The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-77006] The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, doe…
The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de traversal de directorios en libks anteriores a v2.0.11
libks, biblioteca fundamental para productos SignalWire C, contiene un defecto en la función `clean_uri()` del analizador HTTP que permite eludir la validación de rutas. Versiones anteriores a 2.0.11 no rechazarán URIs con segmentos de ruta excesivos, dejando secuencias ".." intactas y facilitando ataques de traversal de directorios. Esto afecta a cualquier aplicación que integre libks y procese solicitudes HTTP, comprometiendo el acceso a archivos sensibles en servidores de telecomunicaciones y plataformas de comunicaciones unificadas.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de condición de carrera en Hoverfly anteriores a v1.12.8
Hoverfly, herramienta de código abierto para simulación de APIs, presenta una vulnerabilidad de race condition en modo Diff que afecta escrituras concurrentes sin sincronización. Cuando múltiples solicitudes proxy se procesan simultáneamente, la función AddDiff() accede sin mutex al mapa compartido responsesDiff, causando fallos fatales en sistemas que dependen de esta herramienta para testing y desarrollo. Empresas en LATAM que usan Hoverfly en entornos de CI/CD o ambientes de validación de APIs están expuestas a interrupciones operacionales.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en Shelf permite inyección SSRF en importación de activos
Shelf, plataforma de gestión de inventarios físicos, contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en versiones anteriores a 1.20.3. Usuarios autenticados con permisos de importación pueden eludir validaciones de URL en la función de importación CSV para ejecutar peticiones HTTP a servidores controlados por atacantes. Afecta principalmente a empresas LATAM que gestionan activos tecnológicos y de infraestructura a través de esta plataforma.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-54135] AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions pr…
AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the HttpServer::Request::content function reads the Content-Length header and direct…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-79393] A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in th…
A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP request containing a wsa5:Action string exceeding 128 bytes.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-79395] An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routin…
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89260] MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback …
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter ent…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89262] MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint…
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.