Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102120] A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obt…
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution conte…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102112] A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained c…
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102113] A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained c…
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the high…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102093] Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not corr…
Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator privileges beyond those the administrative user was authorized to grant.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-53605] Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image fo…
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local p…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-75823] The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned …
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102317] Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed …
Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102676] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100820] Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4…
Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100824] Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and …
Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100801] Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.…
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100807] Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox …
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101860] A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the functio…
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted…
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta de inyección en Zohocorp ManageEngine DDI Central 6.2.0
ManageEngine DDI Central versiones 6.2.0 con build inferior a 6201 contiene una vulnerabilidad de inyección de configuración en Keepalived que permite a operadores autenticados modificar la configuración de alta disponibilidad. Un usuario con rol de operador podría ejecutar comandos con privilegios root en el servidor DDI Central, comprometiendo la integridad de infraestructuras altas de DNS y DHCP en empresas latinoamericanas.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-77203] The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalati…
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100686] Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/group…
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100615] Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowin…
Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover its plaintext credential. Attackers with apikey_manager role can enumerate same-owner API keys, rotate a stronger sibling through the PUT endpoint, and obtain the replacement plaintext secret to authenticate as…
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Codex permite ejecución remota de código sin autorización
OpenClaw Codex anterior a versión 2026.7.1 presenta falla en validación de autorización que permite a usuarios no propietarios con acceso a comandos crear enlaces nativos y ejecutar operaciones con acceso a archivos, herramientas y procesos del sistema. Afecta principalmente a empresas que utilizan esta plataforma para orquestación de infraestructura en entornos cloud de LATAM.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw (npm) permite escalación de privilegios en Gateway
OpenClaw versiones anteriores a 2026.7.1 expone herramientas administrativas restringidas (gateway y cron) a través del endpoint chat.send, permitiendo que usuarios sin permisos de propietario ejecuten operaciones privilegiadas en despliegues con autenticación. Afecta principalmente a infraestructuras en nube que utilizan este paquete npm en sistemas de orquestación y automatización.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-79153] Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in …
Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems.