Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101860] A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the functio…
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted…
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en Thinkware U3000 permite acceso no autorizado remoto
Se identificó una vulnerabilidad (CVSS 7.3) en Thinkware U3000 versiones hasta 1.02.04 que afecta la función PUT_FILE en el archivo /tmp/wpa_supplicant.conf del servicio TCP. Un atacante remoto puede manipular parámetros de ruta para eludir controles de acceso. La vulnerabilidad ha sido divulgada públicamente y cuenta con exploits disponibles, aumentando el riesgo inmediato para organizaciones en LATAM que usan esta plataforma en dispositivos de conectividad empresarial.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100619] Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-l…
Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update public.app_versions.manifest on a version whose storage_provider is 'r2-direct', which i…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97324] A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the …
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86583] The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation…
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with o…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96556] A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function …
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not res…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94425] A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is t…
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/09/2026
[CVE-2026-94036] A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. Th…
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
16/09/2026
Vulnerabilidad de autenticación en plataformas EOS con gRPC y OpenConfig
Plataformas EOS afectadas que implementan autenticación AAA para gRPC en OpenConfig pueden asignar niveles de privilegio incorrectos a usuarios autenticados, permitiendo autorización mediante métodos AAA no autorizados. Este fallo afecta específicamente peticiones gRPC, dejando intacta la seguridad de solicitudes NETCONF y OpenConfig tradicionales, impactando infraestructuras de red que dependen de control granular de acceso en LATAM.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91930] Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the cal…
Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by exploiting insufficient tenant isolation in the organizationuser and workspace endpoints.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90856] A security vulnerability has been detected in SourceCodester College Notes Gallery Management System…
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-86830] Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity C…
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has b…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90787] A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189…
A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might b…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90566] A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5…
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90523] A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eef…
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90493] A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The …
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62102] Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
Subscriber Privilege Escalation in Gato GraphQL
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62106] Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
Subscriber Privilege Escalation in SMS Alert Order Notifications
M Alto vulnerabilidad
11/09/2026
[CVE-2026-8303] Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Instit…
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81805] Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Unauthenticated Privilege Escalation in SiteSkite