Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
14,244
Total alertas
3248
Críticas
10723
Altas
8
Ransomware
963
Esta semana
RSS
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44095] A privilege escalation vulnerability in a script used for network configuration allows a low-privile…
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44096] A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary …
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44097] A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endp…
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44098] This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via …
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-58043] A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree pr…
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-47858] Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes t…
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
M Alto vulnerabilidad
30/07/2026
[CVE-2026-47873] The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of th…
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-47882] When enabling Spring Boot DevTools support for a remote application target (for example a Docker con…
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16524] A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the n…
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16526] A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with in…
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16527] An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP…
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16529] A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network pack…
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15240] The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching…
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the operator who initiated it, allowing a lower-privileged account that an operator is currently switched into to be resolved as that operator and to switch into any permitted account, including an administrator, resulting in full account takeover.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-13178] The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts a…
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-13395] The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize…
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12500] The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX a…
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12687] The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor …
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-1360] The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versio…
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-14356] The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, a…
The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrat…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-48448] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed.