Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-46711] Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.…
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/, /archive/) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-18783] Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Syste…
Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103270] LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without a…
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, and /init_weights_update_group to disrupt inference operations and wedge workers on deployments started with --enable_rl.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102811] Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite…
Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project director…
M Alto vulnerabilidad
29/09/2026
Falta de autenticación en Progress Fiddler Everywhere 8.0.2 permite acceso no autorizado a tokens OAuth
Progress Software Fiddler Everywhere 8.0.2 presenta una vulnerabilidad alta (CVSS 7.7) que permite a un atacante local sin credenciales acceder al backend .NET (Fiddler.WebUi) a través de canales HTTP y SignalR no autenticados. Esto posibilita la generación de tokens OAuth fraudulentos y la lectura del certificado raíz man-in-the-middle. Afecta principalmente a desarrolladores y equipos de testing que utilizan esta herramienta en México y Latinoamérica para análisis de tráfico HTTPS.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102245] A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknow…
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82383] Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote…
Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) on any installed instance, because the setup action remains anonymously reachable after installation and persists configuration without an authorization check. No optional feature or non-default confi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/09/2026
Vulnerabilidad alta en Coolify afecta autenticación de GitHub hasta versión 4.1.0
Se identificó una falla de autenticación en Coolify versiones hasta 4.1.0 en el manejador de configuración de GitHub App, permitiendo bypass de validación del parámetro 'state' en redireccionamientos. La vulnerabilidad es exploitable remotamente y su código de explotación está disponible públicamente. Empresas que usen Coolify como plataforma de despliegue o integración CI/CD deben evaluar inmediatamente su exposición.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100672] The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an …
The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the visitor is authenticated, and it echoes the JSON and calls exit() during the plugin…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-57443] SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 an…
SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configur…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-5267] Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an eve…
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97878] A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anon…
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-81455] Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication f…
Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97231] A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function …
A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86064] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-o…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/api/logs/logSender.go and applied process-wide through Profile.Apply, allowing a remote client to ch…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-18185] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-73588] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing A…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86681] ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permission…
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-75825] ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enab…
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta en Reachy Mini: instalación de aplicaciones sin autenticación
El daemon de Reachy Mini expone una API HTTP sin mecanismos de autenticación en el endpoint POST /apps/install, permitiendo a atacantes instalar aplicaciones maliciosas remotamente en robots controlados por empresas de manufactura y automatización en LATAM. Con puntuación CVSS de 8.8, esta vulnerabilidad representa un riesgo alto para operaciones altas, cadenas de suministro y entornos industriales que dependen de estos dispositivos.