Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 7907 resultados ✕ Limpiar búsqueda
14,046
Total alertas
3206
Críticas
10568
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
30/07/2026
[CVE-2026-54366] CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows un…
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint causing the server to fetch and parse attacker-controlled XML containing external DTD…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-54367] CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated …
CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared encryption key to forge identifiers for any user GUID, including the system-wide cluster …
M Alto vulnerabilidad
30/07/2026
[CVE-2026-54368] CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchE…
CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of the Field parameter directly into SQL query strings to write arbitrary files to th…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-41703] VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor w…
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15397] The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all…
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install a…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-22621] Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PA…
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18360] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18361] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16969] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44106] A privilege escalation vulnerability in the init-script for user-applications allows a low-privilege…
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44107] A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefor…
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44099] A privilege escalation vulnerability in the system configuration allows a low-privileged local user …
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44093] A local privilege escalation vulnerability in the init-script for user-applications allows a low-pri…
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44095] A privilege escalation vulnerability in a script used for network configuration allows a low-privile…
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44096] A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary …
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44097] A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endp…
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44098] This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via …
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-58043] A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree pr…
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-47858] Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes t…
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
M Alto vulnerabilidad
30/07/2026
[CVE-2026-47882] When enabling Spring Boot DevTools support for a remote application target (for example a Docker con…
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically…