Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86482] In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escal…
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84756] Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
Subscriber Privilege Escalation in WCFM Membership
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81769] Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation…
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84115] A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown functio…
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 i…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81297] Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82815] A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file…
A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did n…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82807] A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown …
A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82628] A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function …
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78271] Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Editor Privilege Escalation in FluentCRM Pro
M Alto vulnerabilidad
24/08/2026
[CVE-2026-32561] Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub
M Alto vulnerabilidad
24/08/2026
[CVE-2026-21756] HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unaut…
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73350] Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Unauthenticated Broken Authentication in SupportCandy
M Alto vulnerabilidad
18/08/2026
[CVE-2026-28191] Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
Subscriber Privilege Escalation in The Grid
M Alto vulnerabilidad
17/08/2026
[CVE-2026-15218] A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. Th…
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these exces…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72840] OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants writ…
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66661] Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
Subscriber Privilege Escalation in Directories Pro
M Alto vulnerabilidad
13/08/2026
[CVE-2026-61979] Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
Unauthenticated Privilege Escalation in SAML SP Single Sign On
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28161] Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
Subscriber Privilege Escalation in Service Finder Booking
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27543] Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
Unauthenticated Privilege Escalation in MStore API
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18621] A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can b…
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code…