Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1785
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-78245] A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_upl…
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-78202] A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_setting…
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-55622] Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorizati…
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances they are not authorized to access.…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-55621] Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorizati…
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets in custom volumes they are not au…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-16576] The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 d…
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14-installation capability, allowing users such as Shop Man…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76313] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because th…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-13174] The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting …
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-level access and above to permanently delete other users' accounts.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-50138] goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with Web…
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`…
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta en File Browser permite acceso no autorizado a archivos de otros usuarios
File Browser versiones anteriores a 2.63.20 contiene una falla de aislamiento en los mecanismos de autenticación por proxy y auto-aprovisionamiento de usuarios. Atacantes con credenciales válidas pueden leer, modificar, eliminar y compartir archivos de otros usuarios al explotar la asignación del scope raíz del servidor. Esta vulnerabilidad afecta especialmente a organizaciones en LATAM que despliegan File Browser en entornos multi-usuario o en arquitecturas de proxy.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59501] CWE-284: Improper Access Control
CWE-284: Improper Access Control
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59505] CWE-284: Improper Access Control
CWE-284: Improper Access Control
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13367] IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in th…
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-59914] Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentic…
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-59917] Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Acc…
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13171] The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-l…
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66804] Improper access control in Windows Cross Device Service allows an authorized attacker to elevate pri…
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65773] Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locall…
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
Vulnerabilidad alta de control de acceso en Idurar ERP CRM 4.1.0 expone facturas con datos personales
Idurar IDURAR ERP CRM versión 4.1.0 contiene una vulnerabilidad de control de acceso roto que permite a atacantes no autenticados descargar archivos PDF de facturas con información personal de clientes a través de la ruta /download sin credenciales. Los atacantes pueden enumerar identificadores de MongoDB para acceder a cualquier factura del sistema. Este riesgo es alta para pymes en México y Latinoamérica que procesan datos fiscales y de clientes a través de esta plataforma de gestión empresarial.
M Alto vulnerabilidad
11/08/2026
Vulnerabilidad alta de control de acceso en CSZ CMS 1.3.2 expone datos personales
CSZ CMS 1.3.2 contiene una vulnerabilidad de control de acceso defectuoso que permite a atacantes no autenticados acceder a todos los envíos de formularios de contacto, incluyendo información de identificación personal. El endpoint del visor de envíos carece de validación de autenticación y el framework falla en modo abierto. Empresas en México y LATAM que utilizan esta versión exponen datos de clientes, proveedores y contactos sin necesidad de credenciales.
M Alto vulnerabilidad
11/08/2026
Vulnerabilidad alta de control de acceso en Peppermint permite reconfiguración de SSO/OIDC
Una falla de control de acceso en Peppermint Lab Peppermint (hasta commit ba6e217) permite a usuarios autenticados sin privilegios administrativos modificar la configuración global OIDC/SSO de la plataforma. Un atacante podría redirigir todos los inicios de sesión SSO hacia servidores de identidad controlados, comprometiendo credenciales de usuarios empresariales. Esta vulnerabilidad afecta infraestructuras de autenticación centralizada en organizaciones que utilizan Peppermint como gestor de identidades en entornos cloud.