Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de Negación de Servicio en Net-SNMP hasta 5.9.5.2 afecta monitoreo de infraestructura
Net-SNMP versión 5.9.5.2 y anteriores contiene una vulnerabilidad de denegación de servicio en el módulo SMUX que permite a atacantes remotos no autenticados bloquear indefinidamente el servicio snmpd mediante una conexión sin envío de datos. Afecta sistemas de monitoreo alta en centros de datos, telecomunicaciones y operaciones de TI en LATAM que dependen de SNMP para supervisión de dispositivos de red.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta en libp2p-rendezvous permite desbordamiento de temporizador en clientes
libp2p-rendezvous versión 0.17.1 y anteriores no valida correctamente los valores TTL en respuestas de descubrimiento, permitiendo que servidores rendezvous maliciosos causen pánico en procesos cliente mediante aritmética de temporizador no limitada. Afecta infraestructuras de red descentralizada, nodos blockchain y aplicaciones P2P en México y LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XCS en plugin Kirki para WordPress afecta hasta versión 6.2.0
El plugin Kirki (Freeform Page Builder) para WordPress contiene una vulnerabilidad de Cross-Site Scripting almacenado (XSS) en el parámetro 'comment' que permite a atacantes no autenticados inyectar scripts maliciosos. La falta de sanitización de entrada y escapado de salida afecta todas las versiones hasta 6.2.0, comprometiendo sitios web de empresas, agencias digitales y plataformas de comercio electrónico en LATAM que utilizan este constructor de páginas.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-80469] Ejecución arbitraria de código mediante carga de controladores maliciosos
Una vulnerabilidad alta permite a atacantes ejecutar código arbitrario en sistemas objetivo cargando paquetes de controladores maliciosos que eluden mecanismos de verificación. El impacto afecta principalmente a infraestructuras empresariales en LATAM que utilizan dispositivos de hardware con controladores sin validación adecuada. Requiere interacción del usuario para su explotación.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89174] Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force …
Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de autenticación en WeenyGenius (CVE-2026-89176)
WeenyGenius, sistema de gestión de laboratorios informáticos de Howyar Technologies, presenta una vulnerabilidad de autenticación faltante (CVSS 8.8) que permite a atacantes en la misma red suplantar identidades de estudiantes o docentes sin credenciales. La suplantación de maestros compromete el control remoto de equipos estudiantiles, mientras que la de estudiantes interrumpe operaciones académicas normales. Instituciones educativas en México y LATAM con este software están expuestas en infraestructuras de redes cerradas o híbridas.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89177] WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol…
WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with forged commands to disrupt classroom operations.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89178] WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error…
WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a connection with the attacker.
G Alto vulnerabilidad
11/09/2026
CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
G Alto vulnerabilidad
11/09/2026
CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
11/09/2026
[CVE-2026-85677] The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordP…
The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users to store JavaScript that will execute in the browser of any administrator who reviews the comment queue, and of any visito…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87908] multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1…
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a very large volume of header bytes, forcing the parser to buffer all of them and …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-73784] A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML respons…
A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-73785] A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote un…
A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
M Alto vulnerabilidad
11/09/2026
[CVE-2026-74925] The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capab…
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89060] A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster id…
A flaw was found in multicluster-observability-addon. This vulnerability allows a managed-cluster identity to reference configuration resources outside its designated namespace. This can lead to the disclosure of sensitive hub Secrets to an attacker-controlled managed cluster.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89161] In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a c…
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-81754] The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPres…
The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-81825] The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cros…
The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including,
M Alto vulnerabilidad
11/09/2026
[CVE-2026-19991] The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and inc…
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::…