Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-16181] IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10,…
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105571] A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function …
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early throu…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105382] A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699d…
A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. Th…
M Crítico vulnerabilidad
Hace 4 días
Vulnerabilidad crítica de autorización en Totolik A3002MU 1.0.0-B20230403.1455
Se identificó una debilidad en el router Totolink A3002MU versión 1.0.0-B20230403.1455 que permite bypass de autenticación en la función sub_40FCFC del componente /bin/boa. Un atacante remoto puede manipular el mecanismo de verificación de autorización sin credenciales válidas. El exploit está disponible públicamente, exponiendo dispositivos conectados en redes corporativas y residenciales de LATAM a acceso no autorizado.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización impropia en tacomall 1.0.0 (CVE-2026-102293)
Se identificó una vulnerabilidad de autorización impropia en tacomall versión 1.0.0 que afecta el componente api-admin Backend. Un atacante remoto puede manipular los parámetros isAdmin y jobId en la función OrgStaffServiceImpl.add para eludir controles de acceso y escalar privilegios. El exploit está disponible públicamente, aumentando el riesgo de explotación inmediata en entornos de producción.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100885] A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the…
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this is…
M Alto vulnerabilidad
27/09/2026
[CVE-2025-71426] Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering …
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator,…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97646] A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca5…
A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97324] A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the …
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96762] A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the fu…
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosur…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96556] A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function …
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not res…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-16346] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Crítico vulnerabilidad
22/09/2026
CVE-2026-25254: Autorización deficiente permite Ejecución Remota de Código vía SocketIO
Una vulnerabilidad crítica (CVSS 9.8) en la interfaz SocketIO de múltiples productos permite a atacantes ejecutar código remoto explotando controles de autorización inadecuados. Este vector afecta principalmente servidores web y aplicaciones en tiempo real expuestas en LATAM. La exposición es inmediata si los sistemas están conectados a internet sin restricciones de acceso.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-63330] Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_rec…
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for AdminPermission::RecordingsView. Any authenticated regular user who identifies an active recording can subscribe…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84241] IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due …
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84076] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security res…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84036] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security res…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-77239] WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and aut…
WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypasses row-level security. In src/app/api/flows/[id]/route.ts, src/app/api/flows/[id]/activate/route.ts, and src/app/api/flows/route.ts, a viewer can create, edit, a…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61833] zot is a container image and artifact registry based on the Open Container Initiative Distribution S…
zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete permission. Bearer-authenticated requests also bypass the fine-grained DistSpecAuthzHandl…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10030] IBM MQ Console allows authenticated non-administrative users to create and start queue managers due …
IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorization checks.