Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en hawtio-operator: acceso no autorizado a Secretos del cluster
Se identificó una falla en hawtio-operator que permite al operador acceder a todos los Secretos del cluster mediante permisos excesivos en ClusterRole (create, get, list, update, watch). El compromiso del pod del operador exponendría credenciales y tokens en todos los namespaces, afectando la seguridad de infraestructuras Kubernetes en producción en México y LATAM. El riesgo es alta (CVSS 8.2) para empresas que despliegan este operador en plataformas cloud o on-premises.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80166] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-14444] The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to…
The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, and who possess the access_key, to create a new u…
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en SureCart (WordPress) permite escalada de privilegios y takeover de cuentas
El plugin SureCart para WordPress en versiones anteriores a 4.6.3 contiene una falla de validación que permite a usuarios con permisos de suscriptor modificar direcciones de correo de otros usuarios, incluidos administradores, y tomar control de sus cuentas mediante reset de contraseña. Esta vulnerabilidad afecta directamente a tiendas en línea y plataformas de comercio electrónico operadas en México y Latinoamérica que usan este plugin.
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-86153] A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::Set…
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
M Alto vulnerabilidad
05/09/2026
Escalación de privilegios alta en plugin Abandoned Cart Pro para WooCommerce
El plugin Abandoned Cart Pro para WordPress contiene una vulnerabilidad de escalación de privilegios (CVSS 8.8) que afecta todas las versiones hasta la 10.7.1. Usuarios autenticados pueden ejecutar acciones administrativas sin verificación de capacidades o nonces, comprometiendo tiendas de comercio electrónico en la región. La vulnerabilidad impacta acciones AJAX altas de configuración y envío de correos, exponiendo datos sensibles de clientes y carros abandonados.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75160] An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via th…
An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-15354] The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,…
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85154] WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a…
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes…
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Craft CMS anterior a 5.10.11 permite escalación de privilegios
Craft CMS versiones anteriores a 5.10.11 no valida correctamente la bandera de administrador durante el registro de usuarios, permitiendo que atacantes hereden permisos administrativos registrándose con direcciones de correo de cuentas administrador desactivadas. Esta vulnerabilidad afecta especialmente a instancias con registro público habilitado y verificación de correo desactivada, exponiendo sistemas de gestión de contenidos en empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-80467] The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role subm…
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19453] The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the acco…
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-9055] The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerab…
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when t…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84115] A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown functio…
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 i…
M Crítico vulnerabilidad
01/09/2026
Escalada de privilegios crítica en tema WordPress Nokri - Validación insuficiente de tokens
El tema WordPress Nokri Job Board contiene una vulnerabilidad de escalada de privilegios en versiones hasta 1.6.6 que permite a atacantes no autenticados tomar control de cuentas de usuario. La falla radica en validación deficiente de tokens de reinicio de contraseña en la función `nokri_reset_password()`, que acepta tokens vacíos coincidiendo con valores de metadata desconfigurados. Esto afecta directamente a empresas de LATAM que operan portales de empleo en WordPress, exponiendo bases de datos de candidatos y datos administrativos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79744] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no authorization check. It is protected only by the app-wide authentication middleware and a rate limiter — it never inspects req.user.…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82807] A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown …
A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82860] @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence…
@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82857] hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration…
hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82628] A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function …
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.