Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-75907] The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's…
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-56737] phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authenticati…
phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated attacker can submit an account’s numeric user ID and a valid or brute-forced six-digit TOTP code without first authenticating with the account password, allowing takeover of any 2FA-enabled account, including adm…
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de autenticación en DIAEnergie permite bypass de acceso (CVE-2026-78308)
DIAEnergie anterior a versión 1.11.00.022 contiene una vulnerabilidad de autenticación impropia (CVSS 9.8) que permite a atacantes eludir controles de acceso sin credenciales válidas. Afecta directamente a operadores de infraestructura energética, distribuidoras y gestores de demanda en México y Latinoamérica. El riesgo es crítico en entornos de control industrial y sistemas SCADA.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-19125] The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all version…
The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executi…
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-86248] CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v…
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-75973] Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured w…
Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web application to authenticate a request would be used for all web applications. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through …
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta de autenticación en Apache Doris Frontend permite acceso no autorizado a metadatos
Una falla de autenticación impropia en el servicio de metadatos del Frontend (FE) de Apache Doris permite que atacantes remotos no autenticados accedan a endpoints internos de metadatos. La vulnerabilidad explota configuraciones de red específicas donde se confía en información del cliente sin validación suficiente. Afecta principalmente a sistemas de análisis de datos y datawarehouses en entornos cloud de México y LATAM que utilizan Doris para procesamiento analítico.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-82843] The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID …
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18074] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perfor…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-77244] MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator's globally configured Jira or Confluence credentials. A network client that can reach the MCP endpoint can invoke Atlassian tools as the operator, inc…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65121] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause a…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95271] A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is …
A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-94493] A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unkno…
A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-61687] Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale.…
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Explo…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75878] IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully …
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93559] A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0…
A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The reported GitHub issue was closed automatically due to inactivity.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54510] Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior …
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the selected view to Flask-WTF's process-global exemption set. The is_token_authenticated() function in src/utils/token_auth.py calls extract_token_from_request() and …
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-63472] Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.…
Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented ExternalAuthenticationMethod without requiring verified to be true. In deployments with a custom exte…
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta de bypass de autenticación en AVideo LoginControl (CVE-2026-92914)
AVideo LoginControl contiene una vulnerabilidad de bypass de autenticación en la verificación del segundo factor PGP que compara respuestas usando igualdad débil contra variables de sesión no inicializadas. Un atacante con la contraseña de la víctima puede eludir el segundo factor enviando una solicitud GET sin parámetros a verifyChallenge.json.php, lo que evalúa null == null y marca la autenticación como completada. Esto afecta principalmente a plataformas de video y gestión de contenido en empresas medianas de México y Latinoamérica que utilizan AVideo para portales internos o servicios al cliente.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86707] The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate …
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.