Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-9192] An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11…
An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71277] rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the…
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request gua…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-15372] The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when on…
The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16036] The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured d…
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16055] The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the s…
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any ac…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-15210] The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the …
The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-70482] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming which OAuth client the token was issued to. Anyone holding an access token minted for any client regist…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-18810] A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of …
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack may be performed from remote. The vendor was contacted early about this disclosure.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-63456] Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow…
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta de takeover de cuenta en better-auth 1.1.3 a 1.6.22
better-auth versiones 1.1.3 a 1.6.22 (y pre-lanzamientos 1.7.0-beta.0 a 1.7.0-beta.10) permiten a atacantes secuestrar cuentas de usuarios mediante pre-hijacking de cuenta en flujos de magic-link y email-OTP cuando el registro abierto de email/contraseña está habilitado. Un atacante registra una cuenta con el correo de la víctima sin verificar, luego intercepta el enlace de verificación para tomar control total. Afecta principalmente a aplicaciones web y SaaS en México y LATAM con autenticación sin contraseña.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14830] The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout …
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-14919] The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting tes…
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-12695] The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password …
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows a victim's password to bypass two-factor authentication and gain access to the victim's account, including administrators.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-28323] SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This…
SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-58066] Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7…
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15240] The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching…
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-13690] The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider i…
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user's credentials to bypass the second authentication factor and log in as that user.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-14300] The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin befor…
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid session for any account, including administrators, by requesting a code for an email address they contro…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-54635] pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON…
pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the documented path argument, because setup() stores bearer tokens only under the default suffix paths and never adds the custom path to the token map, so se…
J Alto vulnerabilidad
27/07/2026
[CVE-2026-66014] JFrog Artifactory contains an authentication handling weakness in internal request processing that, …
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.