Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73356] Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Unauthenticated Arbitrary Content Deletion in Breeze
M Alto vulnerabilidad
18/08/2026
[CVE-2026-69189] Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.use…
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history ide…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-32549] Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-32472] Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
Unauthenticated Broken Access Control in Online Contact Widget
M Alto vulnerabilidad
18/08/2026
[CVE-2026-28567] Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
Unauthenticated Broken Access Control in WP Sort Order
M Alto vulnerabilidad
18/08/2026
[CVE-2026-28571] Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
Unauthenticated Broken Access Control in FormyChat
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad de autorización en ArcadeDB versiones ≤26.7.3 permite eliminación no autorizada de funciones
ArcadeDB antes de la versión 26.8.1 contiene una falla de autorización que permite a cualquier usuario con acceso a la base de datos ejecutar DELETE FUNCTION sin validación de permisos. Un atacante puede eliminar funciones del servidor comprometiendo la integridad de aplicaciones que dependen de ArcadeDB en infraestructuras altas de LATAM. La vulnerabilidad (CVSS 7.1) afecta principalmente a bases de datos expuestas internamente o en entornos multi-tenant.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad alta en ArcadeDB: falla de autorización en plugin Gremlin (CVE-2026-75853)
El plugin Gremlin de ArcadeDB versiones ≤26.7.3 autentica conexiones pero no valida permisos de acceso a bases de datos, permitiendo que credenciales válidas accedan a cualquier base de datos sin autorización. Esto afecta directamente a empresas con infraestructuras de bases de datos distribuidas en LATAM que dependen del control granular de accesos. La vulnerabilidad tiene puntuación CVSS 8.8, indicando impacto alta en confidencialidad e integridad de datos.
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad alta de autorización en Plugin API de Grav (CVE-2026-75836)
El plugin API de Grav anterior a versión 1.0.14 presenta una falla en la validación de autorización en el endpoint POST /api/v1/menubar/actions/{plugin}/{action}, permitiendo a usuarios autenticados ejecutar acciones administrativas sin permisos explícitos. La vulnerabilidad afecta principalmente a instancias de Grav con admin-next/API stack expuestas en entornos de producción. Con CVSS 8.8, representa un riesgo alta para sitios web y portales corporativos en LATAM que utilizan este CMS.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-74904] SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kerne…
SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockExist, and getBlockBreadcrumb). These handlers are gated only by basic authentication (model.CheckAuth) and lack publish-access filtering, allowing anonymous publish-mode readers to disclose private block content-derived text, structural metadata, and …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-11801] The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all…
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including register…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-69148] MLflow is an open source AI engineering platform for agents, large language models, and machine lear…
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75109] Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the…
Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-54356] Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/u…
Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentia…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-9771] The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On bu…
The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output buffer (K_SYSCALL_MEMORY_WRITE) and passed the two struct device * arguments, src_dev and dst_dev, directly into the implementation without any obj…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75051] In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was po…
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75044] In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allow…
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16471] Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun…
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16467] Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F…
Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74869] stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message hand…
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message with an arbitrary server ID, receiving live UserUpdate events including display n…