Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 7314 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1272
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta de inyección de comandos OS en CGServiSign de Changing (CVE-2026-15027)
CGServiSign, desarrollado por Changing, contiene una vulnerabilidad de inyección de comandos OS (CVSS 8.8) que permite a atacantes no autenticados ejecutar comandos arbitrarios en computadoras locales mediante ingeniería social. La explotación requiere que la víctima visite una página web maliciosa que interactúe con la interfaz del servicio local, representando riesgo alta para empresas en LATAM que utilizan esta herramienta en estaciones de trabajo y servidores.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91812] A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to …
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91813] A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replace…
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91793] When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotatio…
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application crash.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-82331] Improper link resolution before file access ('link following') vulnerability in the `tar` source plu…
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of this issue is mitigated by: * BuildStream projects should only use trusted sour…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93508] The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-…
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86608] The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of i…
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-82843] The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID …
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-14321] The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it…
The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.
M Alto vulnerabilidad
23/09/2026
[CVE-2022-4997] The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a pay…
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-96257] A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function…
A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91776] TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deseriali…
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers m…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91777] Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs…
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in a…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95927] A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects…
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95926] A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted…
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of the argument test_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95924] A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is …
A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95925] A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected elem…
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96271] Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mut…
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96272] ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search end…
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94367] OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulner…
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5…