Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Dify" — 336 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82377] Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete…
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting ar…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82348] Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user…
Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100872] Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, …
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100686] Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/group…
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100643] SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea …
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100614] Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worke…
Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download and re-upload that object with sanitized metadata. Attackers can silently modify…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-96532] The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership ch…
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100372] ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor…
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97060] X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub…
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97730] In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulne…
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can subm…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97442] In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix invalid data …
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath11k_dp_rx_h_undecap_nwifi() function for the DP_RX_DECAP_TYPE_NATIVE…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-77874] IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerab…
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-18185] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-86708] ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of …
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad de Control de Acceso en ManageEngine OpManager y Firewall Analyzer (CVE-2026-84791)
ManageEngine OpManager y Firewall Analyzer versiones 12.8.710 e inferiores contienen una vulnerabilidad de control de acceso deficiente (CVSS 7.1) que permite a usuarios autenticados con privilegios bajos modificar configuraciones de reportes de Change Management en firewalls fuera de su alcance asignado. Esto afecta directamente a empresas en México y LATAM que utilizan estas soluciones para gestión de infraestructura de red y firewall. El riesgo se incrementa en organizaciones con múltiples equipos de operaciones sin segmentación adecuada de permisos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91793] When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotatio…
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application crash.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93508] The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-…
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17644] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain un…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to gain unauthorized access to sensitive information and modify transaction data due to the use of hard-coded credentials.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17472] IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unau…
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17618] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated at…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.