Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51680] Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unaut…
Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51681] Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un…
Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
Vulnerabilidad crítica en hulumi v1.3.2 permite eludir restricciones IAM en despliegues
Versiones de hulumi anteriores a v1.3.2 contienen una plantilla SCP deficiente que permite a atacantes eludir las protecciones de límites IAM mediante bypass de etiquetas en la creación de recursos. Esta vulnerabilidad afecta directamente a organizaciones que implementan hulumi:iac-role para segregación de accesos en AWS, comprometiendo la integridad de los controles de identidad y acceso en infraestructura como código.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82861] @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attac…
@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82856] @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition ope…
@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-40463] WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log File…
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82607] A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impact…
A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76586] The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does no…
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54745] Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. …
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o…
M Alto vulnerabilidad
27/08/2026
Vulnerabilidad alta en CodeMeter Runtime permite ejecución remota de comandos de configuración
CodeMeter Runtime versiones anteriores a 8.41a y 9.10 presentan una falla en la validación de origen de red que permite a atacantes remotos ejecutar comandos de configuración reservados para clientes locales o de la misma red. Un atacante puede leer datos sensibles del servidor y modificar valores en Server.ini, comprometiendo la integridad de sistemas que utilizan esta tecnología de licenciamiento en infraestructuras altas de empresas en LATAM.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77551] A malicious actor with access to the network and under certain conditions could exploit an Improper …
A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77553] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77557] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77541] A malicious actor with access to the network and high privileges could exploit an Improper Access Co…
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77534] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77536] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77538] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-78236] An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to a…
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65182] Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security co…
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 throu…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-55536] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connectio…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(), allowing start_session commands and unauthorized browser automation. This issue is fixed in version 4.6.58.