Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105147] A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the com…
A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but di…
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en Refly AI (hasta v1.1.0): exposición de credenciales por JWT
Se detectó una vulnerabilidad en el manejador de tokens JWT del componente de configuración de Refly AI versiones hasta 1.1.0, que permite la inyección de credenciales hardcodeadas mediante manipulación de entrada. El ataque es exploitable remotamente y el exploit está público, afectando potencialmente plataformas de IA en empresas de LATAM que usen esta herramienta para automatización y análisis.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97877] A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the functi…
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The …
M Alto vulnerabilidad
20/09/2026
Credenciales hardcodeadas en aiyiyi121 SxDevOps 1.0/1.1 (CVE-2026-93970)
Se ha identificado una vulnerabilidad de severidad alta (CVSS 7.3) en aiyiyi121 SxDevOps 1.0 y 1.1 que expone credenciales hardcodeadas en el archivo backend/sxdevops/settings.py del componente Settings Handler. La falla permite acceso remoto sin autenticación y afecta principalmente a equipos DevOps que utilizan esta plataforma en infraestructuras altas de México y Latinoamérica. El parche identificado es 2b4bf8585c3e731e7a8af30801ea46680bc783f9.
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de credenciales hardcodeadas en aiyiyi121 SxDevOps 1.0/1.1
Se identificó una vulnerabilidad de severidad alta (CVSS 7.3) en aiyiyi121 SxDevOps versiones 1.0 y 1.1 que permite acceso remoto mediante credenciales hardcodeadas en la función ensure_default_superuser del archivo rbac/services.py. Esta falla compromete sistemas de control de acceso y gestión de infraestructura en empresas que utilizan este software en entornos cloud o on-premise en México y LATAM.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90509] A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the fun…
A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early thr…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86673] A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca5…
A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This prod…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad de credenciales codificadas en SourceCodester Syllabus-Aligned LMS 1.0
Se ha identificado una falla de seguridad alta en SourceCodester Syllabus-Aligned Learning Management & Examination System versión 1.0 que expone credenciales codificadas en el archivo db.php. La vulnerabilidad permite acceso remoto sin autenticación y exploits públicos ya están disponibles. Instituciones educativas y organizaciones en LATAM que utilicen este sistema están en riesgo inmediato de comprometer datos académicos y administrativos.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-70403] XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the …
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82808] A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impac…
A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand ab…
M Alto vulnerabilidad
23/08/2026
Vulnerabilidad alta en vas3k TaxHacker permite credenciales hardcodeadas en JWT
Se identificó una vulnerabilidad en vas3k TaxHacker versiones hasta 0.8.2 en el manejador JWT Secret (función envSchema.parse) que permite manipular el parámetro BETTER_AUTH_SECRET, resultando en credenciales hardcodeadas. El ataque es remoto y afecta directamente la autenticación de aplicaciones financieras y de gestión tributaria. Aunque se notificó al desarrollador, no ha respondido con parches disponibles.
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19901] A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown functi…
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The …
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19900] A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown …
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was c…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19750] A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue …
A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SSH. Executing a manipulation can lead to use of hard-coded password. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been published and may be used…
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-35905] T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to conta…
T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the "superadmin" account.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
N Alto vulnerabilidad
03/06/2026
[CVE-2026-22054] Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authentic…
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
N Alto vulnerabilidad
03/06/2026
[CVE-2026-22055] Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated…
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.