Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 41 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-104084] SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and ref…
SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-97212] The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows mu…
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend…
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost 6.20.0-6.57.0: escalación de privilegios en sesiones de administrador
Ghost versiones 6.20.0 a 6.57.0 contienen un fallo en la gestión de sesiones que permite a usuarios autenticados con credenciales de staff suplantary otros administradores sin necesidad de contraseña, eludiendo autenticación de dos factores. Empresas que alojan plataformas Ghost en LATAM enfrentan riesgo alta de compromiso de cuentas administrativas y acceso no autorizado a funciones sensibles de gestión de contenidos.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-88805] Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials…
Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even after the account was logged out. Affected is SUSE Rancher 2.15 before 2.15.2.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100711] froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust c…
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-82566] The Botslab G980H dash camera firmware contains a session management vulnerability in which authenti…
The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism in…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-75907] The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's…
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-79313] webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session manage…
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an expired session whose record has not yet been cleaned up can still be replayed and used, allowing an attacker holding a previously valid session cookie to continue ac…
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-86473] Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token co…
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the v…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81268] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows a…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.