Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79738] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86673] A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca5…
A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This prod…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80134] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad de credenciales codificadas en SourceCodester Syllabus-Aligned LMS 1.0
Se ha identificado una falla de seguridad alta en SourceCodester Syllabus-Aligned Learning Management & Examination System versión 1.0 que expone credenciales codificadas en el archivo db.php. La vulnerabilidad permite acceso remoto sin autenticación y exploits públicos ya están disponibles. Instituciones educativas y organizaciones en LATAM que utilicen este sistema están en riesgo inmediato de comprometer datos académicos y administrativos.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85451] MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSle…
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82808] A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impac…
A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand ab…
M Alto vulnerabilidad
23/08/2026
Vulnerabilidad alta en vas3k TaxHacker permite credenciales hardcodeadas en JWT
Se identificó una vulnerabilidad en vas3k TaxHacker versiones hasta 0.8.2 en el manejador JWT Secret (función envSchema.parse) que permite manipular el parámetro BETTER_AUTH_SECRET, resultando en credenciales hardcodeadas. El ataque es remoto y afecta directamente la autenticación de aplicaciones financieras y de gestión tributaria. Aunque se notificó al desarrollador, no ha respondido con parches disponibles.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta en openssl_encrypt: clave secreta hardcodeada compromete autenticación de API
Versiones de openssl_encrypt anteriores a 1.4.0 contienen una clave secreta predeterminada hardcodeada en la configuración del servidor de telemetría, usada para hash de claves API. Atacantes que conocen este valor pueden falsificar hashes de API para comprometer la autenticación del sistema de telemetría. Esto afecta directamente a infraestructuras en la nube y servidores locales que dependen de esta validación criptográfica.
M Alto vulnerabilidad
17/08/2026
Vulnerabilidad alta en openssl_encrypt: secretos JWT hardcodeados permiten falsificación de tokens
Versiones de openssl_encrypt anteriores a 1.4.0 contienen secretos de firma JWT hardcodeados en config.py que superan validaciones, permitiendo a atacantes con acceso al código fuente forjar tokens válidos para cualquier client_id y acceder sin autorización a APIs de keyserver y telemetría. Afecta especialmente a organizaciones en LATAM que utilizan esta librería en aplicaciones de autenticación y gestión de claves.
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19901] A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown functi…
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The …
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19900] A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown …
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was c…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18164] An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentic…
An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth range to arbitrarily manipulate brain stimulation parameters and state.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-13460] IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded toke…
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster communication and REST API authentication between GUI.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-14866] IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certifica…
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-6374] Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constant…
Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH7601: through 20.07.2026.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/08/2026
Exposición de credenciales en firmware de dispositivos - CVE-2026-49007 (CVSS 7.5)
Vulnerabilidad que permite a atacantes acceder a credenciales iniciales de dispositivos al leer información sin encriptar en el firmware. Afecta múltiples fabricantes y expone interfaces web administrativas. En LATAM, esta falla impacta servidores, equipos de red y sistemas embebidos en infraestructuras altas.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-65313] A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations …
A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-13463] IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the…
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
M Alto vulnerabilidad
27/07/2026
[CVE-2021-32085] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with …
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for o…
M Alto vulnerabilidad
27/07/2026
[CVE-2021-32087] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with …
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileg…