Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1808
Esta semana
RSS
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-68079] In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an …
In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be used more than once." Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-61466] In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and st…
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-63687] Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization…
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP req…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-65583] Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcin…
Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not accepted by default in the validator. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fixes th…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-57817] The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter …
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-66909] Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java …
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage …
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica CVE-2026-5430 en autenticación JWT permite acceso no autorizado
Múltiples fabricantes han reportado una vulnerabilidad crítica (CVSS 10.0) en mecanismos de autenticación JWT que aceptan tokens firmados con algoritmos no configurados explícitamente. Atacantes pueden falsificar tokens JWT con algoritmos alternativos que son validados incorrectamente, permitiendo acceso no autorizado a sistemas, bases de datos y controles administrativos. Este riesgo es especialmente grave en infraestructuras cloud, plataformas de API y soluciones de identidad ampliamente usadas en LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica en productos WSO2: escalación de privilegios mediante tokens insuficientemente restringidos (CVE-2026-1728)
Productos WSO2 emiten tokens a usuarios con pocos privilegios sin restricciones suficientes, permitiendo acceso a APIs REST administrativas. Un atacante con cuenta de bajo privilegio puede ejecutar operaciones administrativas, comprometiendo completamente las cuentas administrativas. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan WSO2 para gestión de identidades y APIs en entornos de producción.
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica en autenticación condicional (CVE-2025-15039) permite bypass de desafíos de autenticación
Un fallo en los scripts de Autenticación Condicional (Adaptive Authentication) permite a atacantes eludir desafíos de autenticación intermedios en configuraciones de múltiples pasos. La vulnerabilidad afecta sistemas de control de acceso empresariales en toda Latinoamérica, poniendo en riesgo aplicaciones críticas que dependen de autenticación multifactor. Con puntuación CVSS 9.4, este vector compromete la integridad de flujos de autenticación en plataformas de identidad y control de acceso.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-16054] The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not preven…
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-12713] The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a para…
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67873] A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding…
A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the current ASDU frame before encoding object fields and segment data
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67870] In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation …
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node pointer to remain NULL while execution continues.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-52466] Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The appl…
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the act…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71319] Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (developm…
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (ws://:/, subprotocol vite-hmr) can call RPC methods, with no token, ha…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-70615] boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-…
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter of the tunnel creation endpoint. Attackers can insert an unrestricted public key entry into authorize…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-48168] PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Acti…
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborat…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-70426] In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.57…
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing agent processes, code running on agents, and attackers with Agent/Connect permission to bypass the JEP-200 deserialization …
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20310] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20303] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are g…