Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 41 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-12650] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-12651] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en Live Composer para WordPress permite inyección de objetos PHP
El plugin Live Composer (versiones hasta 2.1.18) en WordPress es vulnerable a inyección de objetos PHP mediante deserialización de datos no confiables. Atacantes autenticados con acceso de colaborador pueden explotar esta falla para ejecutar código malicioso. Afecta especialmente a sitios pequeños y medianos en LATAM que usan este constructor visual sin actualizar regularmente.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-71374] Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affec…
Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 0…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-76967] SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally…
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This res…
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-7861] Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Custo…
Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad alta en Artemis de EAP: deserialización insegura por defecto
EAP's Artemis permite deserialización de objetos sin validación de seguridad por defecto, exponiendo servidores a ejecución remota de código malicioso. El método ObjectMessage.getObject() utiliza ObjectInputStreamWithClassLoader con listas de permitidos/bloqueados vacías, lo que acepta cualquier clase. Empresas en LATAM con infraestructura Java en producción enfrentan riesgo alta de compromiso de sistemas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de inyección de objetos PHP en plugin Mail Mint para WordPress
El plugin Mail Mint (versiones hasta 1.31.0) para WordPress presenta una vulnerabilidad de inyección de objetos PHP (CVSS 9.8) que permite a atacantes no autenticados ejecutar código arbitrario mediante deserialización de datos no validados en la función 'handle_form_submission'. Afecta principalmente a tiendas WooCommerce y plataformas de email marketing en LATAM que utilizan este plugin.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-19887] The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chose…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-61686] SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveCompon…
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can supply an arbitrary PHP serialized payload. Version 3.0.1 fixes the issue.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84834] Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.
Unauthenticated PHP Object Injection in JobSearch
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84752] Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
Contributor PHP Object Injection in RTMKit
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84753] Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
Unauthenticated PHP Object Injection in Mail Mint
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84670] Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can b…
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84647] In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.5…
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84650] In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from dese…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
M Alto vulnerabilidad
02/09/2026
Inyección de objetos PHP sin autenticación en Ninja Forms - Layout & Styles ≤ 3.0.31
Se ha identificado una vulnerabilidad alta de inyección de objetos PHP sin autenticación en el plugin Ninja Forms - Layout & Styles en versiones 3.0.31 y anteriores. Los atacantes pueden explotar esta falla para ejecutar código malicioso en servidores web, afectando principalmente a sitios WordPress en México y LATAM que utilizan este complemento. La vulnerabilidad tiene un score CVSS de 8.8, indicando riesgo alta de comprometimiento de integridad y disponibilidad.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81283] Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
Subscriber PHP Object Injection in WP User Frontend
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19116] The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from b…
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-71981] Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attacker…
Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout handler. Attackers can pass a base64-encoded serialized payload through this parameter, which is decoded and passed directly to unserialize() without an allow-list, …