Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86437] Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with o…
Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which exec…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86498] In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed…
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
M Alto vulnerabilidad
07/09/2026
[CVE-2026-76560] A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an …
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a dir…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19283] IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator coul…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85619] AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in autho…
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85620] Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validatio…
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85512] A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vu…
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-82302] Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via …
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
M Alto vulnerabilidad
03/09/2026
[CVE-2026-78583] Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipula…
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to rece…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-14199] Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syn…
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while th…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-73475] Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue…
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84354] Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attac…
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84334] Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed …
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84335] Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacke…
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
01/09/2026
[CVE-2026-63137] Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrec…
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-58566] Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote acc…
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad de autorización incorrecta en Dell PowerStore permite escalada de privilegios
Dell PowerStore contiene una vulnerabilidad de autorización incorrecta (CVE-2026-76111, CVSS 8.8) que permite a atacantes autenticados con privilegios bajos ejecutar operaciones administrativas sin autorización. Esta falla de control de acceso afecta directamente a centros de datos y plataformas de almacenamiento empresarial en México y Latinoamérica, comprometiendo la integridad de sistemas altas.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-75921] The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widge…
The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.9 via the upload_template_kit function. This is due to incorrect authorization on the upload_template_kit() AJAX handler, which requires only upload_files capability instea…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81892] EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 an…
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security …
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-53552] Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile…
Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding model.ProjectFile.GetData and model.Project.Ge…