Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 5674 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-85679] The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' …
The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because r…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-81739] The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores …
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-80275] Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to e…
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-101147] The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Pre…
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF at…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-82828] Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unpri…
Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: through 3.3.0.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103536] A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the …
A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103530] A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function f…
A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search Endpoint. Performing a manipulation of the argument provider_options.baseUrl results in server-side request forgery. The attack can be initiated remotely. Applying a patch is the recommended action to fix this issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102142] A system notification template on the Kiteworks appliance was rendered by a template engine that eva…
A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when the notification was next sent.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102143] An unauthenticated attacker could cause a file with attacker-controlled content to be written to the…
An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not properly authenticate the request. This did not by itself result in code execution, which would require a separate vulnerability to place the file in an executable location.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102129] A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was…
A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102130] Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, …
Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102131] Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did n…
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102132] An administrative import function in Kiteworks Core did not verify that the requesting administrator…
An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator privileges, without any action by an existing system administrator.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102125] The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the cod…
The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt th…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102126] A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding …
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative co…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102116] -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to …
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102117] On deployments where the remote-support capability is licensed and enabled, an authenticated System …
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resultin…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102119] A path traversal weakness in an optional, non-default administrative feature allowed an authenticate…
A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102114] A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administr…
A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102108] An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serializ…
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.