Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
19/09/2026
[CVE-2026-92404] The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST A…
The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored WooCommerce API credentials, including a read/write consumer key and secret, from a configured site.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-92708] Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't…
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and uneval functions serialize a typed array by emitting its entire backing ArrayBuffer rather than only the view, so serializing a Node Buffer, whose backing store is a process-wide shared pool, discloses up to 64 KB of unrelated p…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-67100] HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure fla…
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-45726] Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1…
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an authenticated user with the Reader role to retrieve the resource through ResourceServi…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54617] GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an una…
GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in components/launchserver/src/main/java/pro/gravit/launchserver/socket/handlers/fileserver/FileServerHandler.java strips the firs…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-80356] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive …
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92960] vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configura…
vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting all subsequent host DNS queries through an attacker-controlled resolver.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92947] vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host m…
vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations, leading to sensitive data exposure and potential denial-of-service.
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad de autenticación en Grav CMS expone endpoint de depuración
Grav (versiones 1.7.0-1.7.53.2 y 2.0.0-2.0.21) expone el endpoint de profiler Clockwork sin autenticación cuando el depurador está habilitado. Un atacante remoto puede acceder a información sensible del sistema sin credenciales. Afecta principalmente a empresas con sitios en Grav que dejaron debugging activo en producción.
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta en Grav CMS permite evasión del sandbox Twig en versiones 2.0.0-rc.1 a 2.0.21
Grav, un sistema de gestión de contenidos basado en archivos planos, presenta una falla en el sandbox de Twig que permite a usuarios autenticados ejecutar filtros peligrosos (dump, serialize, print_r, vardump, json_encode, yaml_encode) sin restricciones. La vulnerabilidad afecta principalmente a sitios web empresariales y portales de contenido en México y LATAM que utilizan versiones 2.0.0-rc.1 a 2.0.21, exponiendo datos sensibles y permitiendo ejecución de código no autorizada.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92594] Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator an…
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addres…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20360] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Das…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20360 are related to information exposure and insecure handli…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76825] RestrictedPython is a tool that helps define a subset of the Python language for accepting program i…
RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class, a Formatter instance, or a Formatter subclass to restricted code. The string.Formatter methods for…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88065] `tts-be` is a backend for a timetable selector that aims to help students better choose their class …
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthenticated endpoints, a remote attacker can use the backend as an open proxy to bypass …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-76692] A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacen…
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-56882] In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This…
In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91985] Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share …
Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privileges and perform unauthorized writes or administrative actions.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91965] WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php …
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55178] GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map …
GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a second caller-influenced dataset reached through a relationship, map layer, VRT source, externalId lookup, or request body. When a public map references a private…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-45048] Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHan…
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using stateful session storage. A requester who knows a target identity identifier can retrieve another user's active session cre…