Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85128] The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role reques…
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selec…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-12793] The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Esc…
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for un…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55225] Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployme…
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role with full Secret CRUD permissions there and bind it to the Entity Operator Servi…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-65831] ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/…
ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator authorization. GraalPolyglotEngine also permits scripts to bypass the allowedPackages whitelist by reflecting from the bound …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92073] Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1…
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92062] Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, …
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92055] Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Fire…
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92053] Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox…
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92047] Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 a…
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92033] Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92015] Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Fi…
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92017] Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox …
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-14805] The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and incl…
The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in adm…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-75983] The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is v…
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every c…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90856] A security vulnerability has been detected in SourceCodester College Notes Gallery Management System…
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90787] A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189…
A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might b…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-73470] Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or up…
Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 Through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to ve…
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta en Parallels Desktop: escalada de privilegios local vía socket mundial
Parallels Desktop ejecuta el servicio prl_disp_service con permisos root a través de un socket accesible mundialmente (/var/run/prl_disp_service.socket), permitiendo a usuarios locales ejecutar comandos arbitrarios sin validación de firma ni pertenencia a grupos administrativos. La vulnerabilidad afecta principalmente a empresas en México y LATAM que usan Parallels Desktop en infraestructuras de desarrollo, testing y virtualización en macOS, exponiendo sistemas con múltiples usuarios o acceso compartido.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90523] A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eef…
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-86406] The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of t…
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged ro…