Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-26035] An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through …
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad alta de autenticación en plugin WordPress Passwordless Login de VentraConnect
El plugin 'Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login' para WordPress (versiones hasta 1.4.3) contiene un fallo de autenticación que permite eludir el acceso mediante verificación insuficiente del correo electrónico devuelto por Spotify. Un atacante podría acceder a cuentas sin credenciales válidas. Afecta directamente a sitios WordPress en México y LATAM que implementen este plugin con autenticación social.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71467] A flaw was found in search-v2-api. The authentication middleware in the affected component unconditi…
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the `Upgrade: websocket` header. This allows the attacker to bypass authentication and a…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62827] Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate priv…
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-12571] An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeov…
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72922] AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificia…
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webho…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72746] FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a s…
FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTL…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72533] An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privi…
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the autho…
M Alto vulnerabilidad
09/08/2026
Vulnerabilidad alta de autenticación en Task Management System 1.0 de code-projects
Se detectó una vulnerabilidad de autenticación deficiente en el componente Login del archivo /index.php en Task Management System 1.0 de code-projects, permitiendo manipulación del parámetro Password para eludir la autenticación de forma remota. El exploit está públicamente disponible y afecta potencialmente a sistemas de gestión de tareas desplegados en infraestructuras empresariales de LATAM. Con CVSS 7.3, requiere atención inmediata en organizaciones que utilicen esta plataforma.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-48039] Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to…
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authenticatio…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-56793] Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authenticatio…
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16030] The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature…
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-14205] The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when re…
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62896] Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over …
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-56162] Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges …
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-64665] Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, w…
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by emai…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65400] An authentication issue was addressed with improved state management. This issue is fixed in macOS S…
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48087] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the `userId` in the URL belongs to that email. An unauthenticated attacker requests a …
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de elusión de autenticación en plugin WPMU DEV Dashboard para WordPress
El plugin WPMU DEV Dashboard para WordPress (versiones hasta 5.0.0) contiene una vulnerabilidad de elusión de autenticación que afecta sitios no conectados al WPMU DEV Hub. La clave API del sitio permanece vacía en la configuración predeterminada, permitiendo falsificar firmas de solicitud WDP-AUTH. Esto expone a empresas mexicanas y latinoamericanas con sitios WordPress multisite a acceso no autorizado a funcionalidades administrativas altas.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18990] A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file…
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.