Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-93882] The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vul…
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.4.8 via the CourseMaterialTemplate::render_material_items() callback exposed on the public lp-ajax-handle (load_content_via_ajax) endpoint. The endpoint is explicitly listed in the AbstractAjax no-nonce allowlist and per…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100268] In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other proj…
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103054] AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that a…
AiSOC versions before 12.0.0 contain an authorization bypass vulnerability in the MSSP module that allows authenticated users to add arbitrary tenants to portfolios they own. Attackers can submit tenant UUIDs via the add_tenants_to_portfolio endpoint to claim unclaimed tenants and read their security alerts, incidents, and posture metrics without consent.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102876] SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_aut…
SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, cr…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93538] A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated clus…
A cross-tenant authorization issue was discovered in SUSE Rancher Fleet. During agent-initiated cluster registration, cluster labels supplied by the registering agent, including labels in the reserved management.cattle.io/ namespace such as the cluster display name label, were applied to the resulting upstream Cluster object. Because Fleet resolves GitRepo and Bundle targets from those cluster lab…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82323] Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies In…
Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82348] Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user…
Authorization Bypass Through User-Controlled Key in Apache Roller 6.1.5 allows an authenticated user with authoring rights on one weblog to read, modify, or delete resources belonging to another weblog through unscoped identifier-based lookups. This affects multi-user installations where users are intended to be isolated between weblogs; no optional feature or non-default configuration is required…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100885] A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the…
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this is…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100679] stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowin…
stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypass MFA by using their own valid ticket with another user's session token. Attackers can obtain a ticket from their own account and use it with a victim's session token to disable TOTP, view recovery codes, or perform other sensitive operations without providing the victim's creden…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100670] Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and accoun…
Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested `access[admin][super]`) matches no blueprint rule, survives BlueprintSchema::filterArray() an…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100627] Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw i…
Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes with checkPermission(c, 'channel.promote_bundle', { appId: body.app_id }) and omits the request's channel_id. Because the omitted scope field is passed t…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100614] Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worke…
Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download and re-upload that object with sanitized metadata. Attackers can silently modify…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100618] Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id…
Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a user-controlled `icon` value, normalizes it, and stores it in public.apps.icon_url without verifying that the image path belongs to the target app's own image namespace (e.g. org/{owner_org}/{app_id}/...). Updating apps.icon_url fires the on_app_update trigger, whose worker reads…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100610] Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history withou…
Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory rows selected solely by an attacker-supplied chatflowid, and patchDeleteUpsertHistory() deletes rows by an attacker-supplied array of record UUIDs. As a…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100612] Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.…
Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_provider_client_update_guard()) that freezes only the dns_verified_at, domain, status and enforce_sso columns; provider_id (as well as metadata_url and attribute_map…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad de suplantación de identidad en OpenClaw (npm) permite escalación de privilegios
El paquete npm 'openclaw' anterior a versión 2026.7.1 presenta una falla alta en la validación de identidad del solicitante en arquitecturas de Gateway con autenticación. Un atacante con permisos de escritura puede suplantar la identidad de otros usuarios para ejecutar acciones de canal no autorizadas. Afecta principalmente a sistemas de integración empresarial en entornos cloud y on-premise en LATAM.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97060] X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub…
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97646] A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca5…
A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-77293] TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:…
TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/services/collabService.ts resolves the target only by note and file identifiers without requiring the file to belong to that trip. A user with edit access to any tri…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96762] A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the fu…
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosur…