Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1805
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad XSS almacenado alta en WPForms Pro para WordPress
El complemento WPForms Pro para WordPress es vulnerable a inyección de scripts almacenados en campos de texto simple y párrafo (versiones hasta 2.0.0.2) debido a sanitización insuficiente. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas comprometidas. Este riesgo es alta para sitios comerciales, de servicios y gobierno en LATAM que dependen de formularios para captura de datos.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta en Multicluster Engine (MCE) permite eliminar clústeres sin autorización
Se identificó un fallo en el componente clusterclaims-controller de Multicluster Engine (MCE) que permite a usuarios con permisos estándar manipular el campo `spec.namespace` para especificar y eliminar cualquier ManagedCluster, incluyendo el hub local-cluster o clústeres de otros inquilinos. La ausencia de validación de propiedad (ownership check) expone infraestructuras multiclúster en entornos empresariales de México y LATAM a pérdida de disponibilidad y movimientos laterales entre tenants.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-77642] tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signatu…
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-72818] The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app…
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partitioned in exponentially many ways, and because the branch also requires a trailing top-level domain t…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-72848] SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente…
SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to self.scrape_all([loc.text], "xml"), which reaches WebBaseLoader.scrape_all and an aiohttp GET, with no dom…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-72860] The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues se…
The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-69855] Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di…
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-69519] Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor…
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-69543] Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat…
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-69558] Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized …
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-69419] Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe…
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-66800] Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose…
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-55765] CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. …
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pg_stat_statements was pr…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-55013] Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per…
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-49436] LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API…
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrati…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-46355] BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu…
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse that participant's session and impersonate the participant in the same meeting b…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-46682] BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authentica…
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. The method interpolated those values into breakout room visibility queries, allowing arbitrary SQL exe…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-49217] Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati…
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enabled. Upgrade to Mailu 2024.06.52 to receive a patch or, as a workaround, turn the REST API off.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-19442] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtua…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-19446] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a cr…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resulting in complete system unavailability and requiring an LPAR restart.