Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78462] Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attack…
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86725] AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerabili…
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored access_token and refresh_token, then delete the compromised record to destroy the victim…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86720] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of l…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, Facebook, …
M Alto vulnerabilidad
07/09/2026
Bypass de autorización alta en SourceCodester Syllabus-Aligned LMS 1.0 (CVE-2026-86277)
Se ha identificado una vulnerabilidad de bypass de autorización en SourceCodester Syllabus-Aligned Learning Management & Examination System versión 1.0, específicamente en el archivo delete_exam.php. Un atacante remoto puede manipular el parámetro ID para eludir controles de acceso y eliminar exámenes sin autorización. La vulnerabilidad con CVSS 7.3 afecta instituciones educativas en LATAM que utilizan este LMS para gestión académica y evaluaciones.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86263] A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. …
A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now publi…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86261] A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8…
A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to authorization bypass. The attack can be executed remotely. The exploit has been made …
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86262] A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d6…
A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument userID/id leads to authorization bypass. The attack is possible to be carried out rem…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-16310] The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over t…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85638] A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/us…
A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85607] Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (mess…
Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they query the database by caller-supplied conversation or message ID without verifying…
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de omisión de autorización en Snipe-IT anterior a v8.6.2 afecta gestión de activos
Snipe-IT versiones anteriores a 8.6.2 contienen una falla de autorización en reportes de aceptación de checkout cuando está habilitado el soporte multi-empresa. Usuarios autenticados con permiso reports.view pueden enumerar IDs secuenciales, eliminar o enviar recordatorios de aceptaciones de otras empresas, comprometiendo la integridad de datos de auditoría y control de activos en organizaciones con múltiples sucursales en LATAM.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de omisión de autorización en snipe-it anterior a 8.6.3 afecta gestión de usuarios
snipe-it versiones anteriores a 8.6.3 contienen una vulnerabilidad de omisión de autorización en la funcionalidad de eliminación masiva que permite a usuarios restringidos eliminar de forma reversible usuarios fuera de su alcance autorizado. Los atacantes pueden incluir IDs de usuario no autorizados en solicitudes de eliminación masiva para eludir restricciones a nivel de instancia y modificar o desactivar cuentas que no deberían poder acceder. Esta vulnerabilidad afecta directamente a empresas LATAM que utilizan snipe-it para gestión de inventario de TI.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-16281] The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can ed…
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-83711] Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an u…
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85378] A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601…
A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is pub…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-69857] Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to…
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84836] Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping
M Alto vulnerabilidad
03/09/2026
[CVE-2026-75035] A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector nami…
A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affec…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85211] Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects …
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85214] vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users …
vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service.