Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87072] Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87569] Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker lev…
Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87537] Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacke…
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87487] Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacke…
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86819] Waves Central for macOS contains a local privilege escalation in the privileged helper service. The …
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier and Team ID). A local, authenticated user can execute code within the vendor-signed…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83942] Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73014] Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privil…
Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69724] Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code o…
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69553] Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a …
Missing authorization in Windows Hyper-V allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69465] Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code o…
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69377] Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to ele…
Missing authorization in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69380] Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileg…
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-47625] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse miss…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86665] A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the functio…
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-18851] Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8…
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
Plugin Event Tickets and Registration para WordPress vulnerable a modificación no autorizada de credenciales Stripe
El plugin Event Tickets and Registration en WordPress (versiones hasta 5.27.4) presenta una falla alta de validación de permisos en el endpoint de retorno OAuth de Stripe, permitiendo que atacantes no autenticados sobrescriban credenciales del comerciante (tokens de acceso, claves públicas e ID de cuenta). Esto afecta directamente a tiendas en línea, plataformas de eventos y sitios de registro en México y LATAM que procesan pagos a través de Stripe.
M Alto vulnerabilidad
08/09/2026
Plugin EDD Product Catalog Feed para WordPress vulnerable a eliminación no autorizada de datos
El plugin EDD Product Catalog Feed by PixelYourSite en WordPress (versiones hasta 1.0.2) contiene una falta de validación de permisos en la función wpeddpcf_delete_feed, permitiendo a usuarios autenticados con acceso de suscriptor o superior eliminar valores de opciones arbitrarias. Esto puede provocar denegación de servicio y corrupción de datos altas en tiendas en línea y plataformas de comercio electrónico en LATAM.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81781] Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting In…
Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81790] Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez…
Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86438] Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire a…
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.