Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101077] A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the…
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82383] Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote…
Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default confi…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-101065] Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, th…
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca…
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en Coolify afecta autenticación de GitHub hasta versión 4.1.0
Se identificó una falla de autenticación en Coolify versiones hasta 4.1.0 en el manejador de configuración de GitHub App, permitiendo bypass de validación del parámetro 'state' en redireccionamientos. La vulnerabilidad es exploitable remotamente y su código de explotación está disponible públicamente. Empresas que usen Coolify como plataforma de despliegue o integración CI/CD deben evaluar inmediatamente su exposición.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100672] The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an …
The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the visitor is authenticated, and it echoes the JSON and calls exit() during the plugin…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-57443] SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 an…
SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configur…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-5267] Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an eve…
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97878] A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anon…
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-81455] Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication f…
Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-13249] An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web manageme…
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97231] A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function …
A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86064] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-o…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/api/logs/logSender.go and applied process-wide through Profile.Apply, allowing a remote client to ch…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-18185] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-73588] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing A…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86681] ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permission…
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-75825] ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enab…
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta en Reachy Mini: instalación de aplicaciones sin autenticación
El daemon de Reachy Mini expone una API HTTP sin mecanismos de autenticación en el endpoint POST /apps/install, permitiendo a atacantes instalar aplicaciones maliciosas remotamente en robots controlados por empresas de manufactura y automatización en LATAM. Con puntuación CVSS de 8.8, esta vulnerabilidad representa un riesgo alto para operaciones altas, cadenas de suministro y entornos industriales que dependen de estos dispositivos.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17635] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perfor…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77248] MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while upload_attachment accepts an unrestricted file_path. An unauthenticated network caller can read files available to the MCP process, upload them to an attacker-select…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-77254] MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use globally configured Jira or Confluence credentials. A network caller can perform operations with the operator account's permissions unless the deployment has an independ…