Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80191] GROWI applies its page-viewer permission check to attachment requests only when the request carries …
GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a request that carries no session skips the check entirely and the handler returns the file. The routes reached this way, /atta…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80193] Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller…
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79286] Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a …
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-69104] An authenticated user may initiate repository migration operations without required repository permi…
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55528] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is configured. This issue is fixed in version 1.6.58.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de omisión de autorización en Ech0 anterior a 4.5.1 permite acceso a endpoints administrativos
Ech0 versiones anteriores a 4.5.1 presentan una falla de autorización donde los tokens de sesión no validan permisos en el middleware RequireScopes, permitiendo que usuarios autenticados sin privilegios de administrador accedan a endpoints protegidos. Los atacantes pueden extraer registros del sistema, estadísticas de visitantes, correos de usuarios y suscribirse a logs en vivo mediante WebSocket utilizando tokens de sesión válidos.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-66109] A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vu…
A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-19892] The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover i…
The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes i…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-56707] Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability …
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforc…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71504] Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that…
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76847] act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actio…
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and never check that it belongs to the requester: validateRunIDV4 in pkg/artifacts/art…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-28190] Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
Subscriber Broken Access Control in ProLancer Element
M Alto vulnerabilidad
24/08/2026
[CVE-2026-28153] Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notificatio…
Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More
M Alto vulnerabilidad
24/08/2026
[CVE-2026-19200] The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other is…
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.
M Alto vulnerabilidad
21/08/2026
Vulnerabilidad de divulgación de información en Combodo iTop anterior a versión 3.2.3
Combodo iTop, herramienta web de gestión de servicios TI utilizada en empresas mexicanas y latinoamericanas, presenta una vulnerabilidad que permite a usuarios no autorizados acceder a información de objetos mediante operaciones de búsqueda. La falla afecta versiones anteriores a 3.2.3 con severidad CVSS 8.8, comprometiendo la confidencialidad de datos sensibles de configuración y activos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/08/2026
[CVE-2026-75932] Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom doma…
Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client ID and Client Secret if the victim is using an OAuth provider.
M Alto vulnerabilidad
21/08/2026
Vulnerabilidad de autorización en API de Reconmap permite acceso no autenticado a reportes
Reconmap presenta una falla en su política de autorización que permite a usuarios anónimos acceder a la acción PreviewReport en ReportsController.cs, eludiendo el requisito de autenticación administrativa. Esta vulnerabilidad (CVSS 7.5) afecta directamente a empresas que utilizan Reconmap para pentesting y análisis de seguridad, exponiendo reportes confidenciales de evaluaciones de vulnerabilidades.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-76633] WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a…
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routin…
M Alto vulnerabilidad
20/08/2026
Control de Acceso Roto sin Autenticación en EPROLO Dropshipping <= 2.4.2
Se ha identificado una vulnerabilidad de control de acceso roto sin autenticación en EPROLO Dropshipping versiones 2.4.2 y anteriores, con puntuación CVSS de 7.1. Esta falla permite a actores no autenticados acceder a funcionalidades sensibles del sistema, comprometiendo datos de inventario, pedidos y configuraciones altas de tiendas dropshipping en México y Latinoamérica. El impacto es significativo para PyMEs que dependen de esta plataforma para sus operaciones de comercio electrónico.
M Alto vulnerabilidad
20/08/2026
Control de acceso roto sin autenticación en Koji versiones <= 2.2.1
Se ha identificado una vulnerabilidad de control de acceso quebrantado en Koji