Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-104075] TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authenticat…
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript val…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39793] Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39769] Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
Unauthenticated Broken Authentication in Graphina
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad de bypass de autenticación en Taxi Booking Manager for WooCommerce
Taxi Booking Manager for WooCommerce (versiones anteriores a 2.0.8) contiene una vulnerabilidad de bypass de autenticación que permite a atacantes eludir controles de acceso mediante canales alternativos. Esto afecta directamente a agencias de transporte y plataformas de reserva en LATAM que utilizan este plugin, exponiendo datos de clientes y operaciones de negocio. El CVSS 7.3 indica alto riesgo de explotación remota sin autenticación previa.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-58269] Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Pri…
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker with stolen or phished credentials can bypass 2FA in a single request…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-62101] Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Unauthenticated Broken Authentication in EduAdmin Booking
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27546] An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function…
An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57134] PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src…
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-91143] goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allo…
goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81796] Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Unauthenticated Broken Authentication in WP Travel
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81783] Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Subscriber Broken Authentication in MailMunch – Grow your Email List
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88861] Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched versio…
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been used for the session: the Edge JWT middleware (foundJWT() in supabase/functions/_bac…