Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta en hMailServer: validación de Host faltante permite ataque de fuerza bruta
Progressive Robot hMailServer versiones 6.0.0 a 6.3.5 contienen deficiencias en la validación de encabezados HTTP y falta de limitación de intentos fallidos en su API REST, permitiendo ataques de DNS rebinding para comprometer credenciales de administrador. Empresas en LATAM que utilizan este servidor de correo son vulnerables a toma de control administrativo si el listener REST está habilitado, incluso en configuraciones de loopback.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107230] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT prox…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105783] Joplin is an open source note-taking and to-do application that organises notes and lists into noteb…
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP o…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102878] mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API t…
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers can craft malicious web pages that make cross-origin requests to the local server and invoke browser automation tools including script execution, page content reading, and screenshot capture.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102673] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popup…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102675] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue compl…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100642] SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the …
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100646] SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3,…
SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cr…
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en paquete OpenClaw (npm) permite falsificación de aprobaciones
OpenClaw versiones anteriores a 2026.7.1 presenta un defecto en el enlace de reacciones de aprobación en Signal que permite que una aprobación destinada a una solicitud estructurada se adjunte incorrectamente a mensajes de texto ordinarios en la misma conversación. Esto podría resultar en que una reacción de un aprobador a un mensaje no relacionado sea interpretada como aprobación de una solicitud, comprometiendo controles de autorización en flujos de trabajo altas de empresas que utilizan esta dependencia npm.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en plugin YOP Poll de WordPress permite robo de credenciales de administrador
El plugin YOP Poll para WordPress (versiones hasta 7.0.10) contiene una falla de validación de origen que permite a atacantes no autenticados robar tokens REST (nonces) de administradores mediante postMessage() con targetOrigin comodín. Los atacantes pueden utilizar estos tokens para cambiar la dirección de correo de cuentas administrativas y comprometer completamente los sitios WordPress. Esta vulnerabilidad afecta directamente a pequeñas y medianas empresas en México y LATAM que utilizan WordPress con plugins no actualizados.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94243] A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin eviden…
A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad alta en PraisonAI permite ataques de DNS rebinding en sistemas locales
PraisonAI (versiones 0.6.0 a 1.6.59 en praisonaiagents y 3.10.0 a 4.6.59 en PraisonAI) expone endpoints legados /sse y /messages/ sin validación de Host, Origin ni autenticación, permitiendo que sitios maliciosos ejecuten ataques de DNS rebinding contra instancias locales. Afecta especialmente a empresas que ejecutan sistemas multi-agente en infraestructura interna o en la nube privada. El CVSS de 8.3 refleja alto riesgo de compromiso de datos y control remoto.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82438] Description Three separate mechanisms allowed a web page on an unrelated origin to read responses t…
Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while also sending `Access-Control-Allow-Credentials: true`. The published security model documents a permissive `Access-Control-Allow-Origin: *` …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78807] An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper netwo…
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69680] Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a ne…
Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85152] undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the ca…
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant …
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84482] WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_d…
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55532] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type: text/plain requests without preflight and invoke tools/call without an API key, including file writes that persist agent …
M Alto vulnerabilidad
21/08/2026
[CVE-2026-62316] Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t…
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through …
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74802] SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-onl…
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally return true. Attackers can craft malicious webpages that establish WebSocket connections to this endpoint and direct the SiYuan kernel process to proxy arbitrary network traffic to attac…