Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75105] phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary …
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database primary key to fetch an address without confirming the address belongs to the authorized subnet. An unauthenticated party ho…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-74877] openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the …
openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restriction.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19979] A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE…
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The vendor explains: "…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73841] OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0…
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72629] Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-…
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72741] Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function tha…
Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and access or modify another enterprise's services, plugins, environment variables, a…
M Alto vulnerabilidad
13/08/2026
File Browser anterior a v2.63.22: bypass de controles de acceso en operaciones recursivas
File Browser versiones anteriores a la 2.63.22 presentan una vulnerabilidad de validación deficiente que permite a usuarios autenticados eludir controles de acceso basados en rutas durante operaciones de copia, renombre y eliminación recursiva. Un atacante interno puede manipular archivos denegados operando sobre directorios padre permitidos, comprometiendo el aislamiento por reglas y afectando confidencialidad e integridad de datos en servidores empresariales.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18945] The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its…
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73303] Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibas…
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attacker who obtains a victim account identifier can start the email-change workflow for the victim, receive and submit the verification code through POST …
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19228] GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 …
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of identity information supplied in requests.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-47231] Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-file…
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUploadRight()` on the URL parameter `folder_uuid`. The `move_save` handler then operates on a *separate* URL parameter `file_uuid` and calls `File::moveToFolder($destFolderUUID)`. `File::moveToFolder()` checks the upload right on t…
M Alto vulnerabilidad
12/08/2026
CVE-2026-66878: Vulnerabilidad de divulgación de información en multicloud-operators-subscription
Se ha identificado una falla en multicloud-operators-subscription que permite a administradores de namespace con privilegios acceder a secretos almacenados en otros espacios de nombres mediante manipulación del campo Channel.Spec.SecretRef.Namespace. Esta vulnerabilidad (CVSS 7.7) expone credenciales, tokens API y datos sensibles en entornos multicloud comúnmente utilizados en infraestructuras híbridas de empresas latinoamericanas. El riesgo se amplifica en organizaciones con múltiples equipos compartiendo clusters Kubernetes.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-69119] Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service…
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only validates that a caller presents a valid GitHub OAuth token without verifying owners…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58650] Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attack…
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-56721] CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure dir…
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72546] An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any aut…
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees and orders into events belonging to other accounts via the postInviteAttendee endpoint. The endpoint loads the target event by ID without scoping the query to the authenticated organiser account. An attacker can modify event data and financial records a…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72547] An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any aut…
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attendees into events belonging to other accounts via the postImportAttendee endpoint. The endpoint loads the target event by ID without verifying ownership against the requesting organiser account. An attacker can inject bulk attendee data into any event in…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72543] An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows una…
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records i…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72545] An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows una…
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without creden…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-19424] Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability.…
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.