Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1800
Esta semana
RSS
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16401] Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox …
Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16396] Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.…
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16379] Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo…
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16371] Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, …
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16372] Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo…
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16365] Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and …
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16366] Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 a…
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/07/2026
[CVE-2026-55550] NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is a…
NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, and deletion to `manager` and `admin` roles. However, in version 0.12.1, the MCP product tools expose the same write operations through `/api/mcp/mcp` using user-generated Bearer tokens and do n…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-13142] The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce r…
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, …
M Alto vulnerabilidad
18/07/2026
[CVE-2026-47868] VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with …
VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
M Alto vulnerabilidad
18/07/2026
[CVE-2026-47870] VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated us…
VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31.2.2 (fixed in 31.2.2-2p3) 30.1.1 through 30.2.6 (fixed in 30.2.7) 22.1.1 through 22.1.7 (fixed in 30.2.7)
M Alto vulnerabilidad
17/07/2026
[CVE-2026-11961] The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the members…
The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exis…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-43978] wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can…
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. Once a trainer performs a legitimate switch into a low-privileged user, the session flag trainer.identity is set and this flag alone bypasses the permission ch…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15103] The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress…
The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to validate the `group_id` path parameter against an allowlist of permitted option names before passing it directly to `get_op…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-13741] The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege…
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administr…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12525] The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be wri…
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) fe…
B Alto vulnerabilidad
15/07/2026
[CVE-2026-53515] Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11,…
Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach a new SSO provider to that organization because registerSSOProvider checks only for a membership row and does not require an owner or admin role, allowing attacker-controlled OIDC or SAML providers to driv…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-57996] phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint tha…
phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create SuperAdmin accounts. A delegated administrator with USER_ADD/EDIT/DELETE permissions can call POST /admin/api/user/add with isSuperAdmin: true and attacker-chosen credentials to create a SuperAdmin account, then authenticate as that account to achieve…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50391] Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privi…
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50343] Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate …
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.