Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 50 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60327] Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic…
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impa…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-47037] Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentic…
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version that is affected is 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-53591] FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version …
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted `In-Reply-To` header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a …
S Alto vulnerabilidad
20/07/2026
[CVE-2026-12341] This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unautho…
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth bearer tokens.
N Alto vulnerabilidad
20/07/2026
[CVE-2026-55626] xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session …
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX domain sockets, the Xvnc process is launched with insufficient authentication mechanisms. A local authenticated attacker could exploit this vulnerability to bypass intended session isolation, allowing them to unauthorizedly view or control the active d…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-48812] FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version …
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because this route is unauthenticated and the file path is deterministic, an unauthenticated remote attacker can download any attachment that was creat…
M Alto vulnerabilidad
19/07/2026
[CVE-2026-16210] A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_acti…
A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The project was informed of the problem early through an issue re…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
19/07/2026
[CVE-2026-16209] A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function o…
A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is bd4891c60315f17611a3b7a651ffe0fba7cfe71e. Ap…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12585] The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity…
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled.
M Alto vulnerabilidad
15/07/2026
[CVE-2026-46485] Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow …
Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the main config.yaml through the config-saving functionality despite configured permissions, allowing unauthorized modification of dashboard configuration and potential service disruption. This issue is fixed in version 4.0.8…
B Alto vulnerabilidad
15/07/2026
[CVE-2026-53514] Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1…
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside the invited mailbox and requireEmailVerificationOnInvitation: true is not enabled, the organization plugin's acceptInvitation, rejectInvitation, getInvitation, and listUserInvitations recipient endpoints use session.user.email and an invita…
B Alto vulnerabilidad
15/07/2026
[CVE-2026-53516] Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better A…
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking when the OAuth provider asserts email_verified: true without requiring the local user row's emailVerified field to also be true, allowing an attacker who pre-registers a victim email through /sign-up/email to…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-59955] Apollo is a reliable configuration management system suitable for microservice configuration managem…
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because requests under /configfiles/raw/{appId}/{clusterName}/{namespace} are parsed for authentication as appId raw instead of the a…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-59954] Apollo is a reliable configuration management system suitable for microservice configuration managem…
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled because ConfigService can accept a non-canonical appId variant during authentication while downstream request handling resolves it to the…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-61435] PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints…
PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent_invoke.py) when PRAISONAI_CALL_AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the client-controlled HTTP Host header. A remote, una…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/07/2026
[CVE-2026-61436] PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing …
PraisonAI before 4.6.78 fails to verify Svix webhook signatures in AgentMail webhook mode, allowing unauthenticated attackers to forge message.received events. Attackers can send crafted JSON payloads to the webhook endpoint to invoke configured agents with arbitrary sender addresses and message content.
M Alto vulnerabilidad
15/07/2026
[CVE-2026-12281] The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode…
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automat…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50365] Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges ove…
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-56169] Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges …
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-57107] Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges …
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.