Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69282] Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code…
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69273] Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code…
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69268] Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code…
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86666] A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function …
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not res…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86305] A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf4…
A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and …
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86272] A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.600…
A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en Bifrost HTTP transport permite ejecución de código remoto sin autenticación
Bifrost HTTP transport anterior a versión 2.0.0 permite a atacantes no autenticados cargar y ejecutar plugins maliciosos a través de POST /api/plugins cuando la autenticación de gestión está deshabilitada (configuración por defecto). El cargador de objetos compartidos descarga archivos desde URLs HTTP y los ejecuta como librerías dinámicas en Go, comprometiendo completamente servidores en infraestructuras altas de LATAM. Afecta especialmente a plataformas de integración y orquestación de datos sin hardening de seguridad.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85147] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85208] A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affecte…
A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller. Performing a manipulation of the argument image results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the pub…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84668] Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider …
Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-51766] Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un…
Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out reboot commands to mesh slaves via sending a crafted MQTT message to the cs_broker component.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84128] Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155.
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84117] Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad de autenticación faltante en AVideo permite modificar transmisiones programadas
AVideo presenta una vulnerabilidad alta (CVSS 8.2) en el módulo de transmisión en vivo que permite a atacantes no autenticados modificar el estado de transmisiones programadas mediante solicitudes POST manipuladas. Esta vulnerabilidad afecta principalmente a plataformas de streaming y educativas en LATAM que utilizan este software de código abierto. Los atacantes pueden deshabilitar o sabotear retransmisiones sin acceso previo al sistema.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82921] A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_typ…
A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82815] A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file…
A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did n…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82861] @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attac…
@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-40463] WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log File…
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82607] A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impact…
A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used.…
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76586] The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does no…
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.