Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-75973] Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured w…
Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the realm for the first web application to authenticate a request would be used for all web applications. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through …
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta de autenticación en Apache Doris Frontend permite acceso no autorizado a metadatos
Una falla de autenticación impropia en el servicio de metadatos del Frontend (FE) de Apache Doris permite que atacantes remotos no autenticados accedan a endpoints internos de metadatos. La vulnerabilidad explota configuraciones de red específicas donde se confía en información del cliente sin validación suficiente. Afecta principalmente a sistemas de análisis de datos y datawarehouses en entornos cloud de México y LATAM que utilizan Doris para procesamiento analítico.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18074] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perfor…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65121] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause a…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95271] A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is …
A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-61687] Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale.…
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Explo…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93559] A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0…
A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The reported GitHub issue was closed automatically due to inactivity.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54510] Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior …
Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the selected view to Flask-WTF's process-global exemption set. The is_token_authenticated() function in src/utils/token_auth.py calls extract_token_from_request() and …
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta de bypass de autenticación en AVideo LoginControl (CVE-2026-92914)
AVideo LoginControl contiene una vulnerabilidad de bypass de autenticación en la verificación del segundo factor PGP que compara respuestas usando igualdad débil contra variables de sesión no inicializadas. Un atacante con la contraseña de la víctima puede eludir el segundo factor enviando una solicitud GET sin parámetros a verifyChallenge.json.php, lo que evalúa null == null y marca la autenticación como completada. Esto afecta principalmente a plataformas de video y gestión de contenido en empresas medianas de México y Latinoamérica que utilizan AVideo para portales internos o servicios al cliente.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92578] WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password h…
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password v…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92792] OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied …
OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verification by including the test_purpose key in evidence and providing enrolled measure and serial number pairs from the allowlist to gain unauthorized access.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92401] A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. Th…
A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor…
M Alto vulnerabilidad
16/09/2026
[CVE-2025-43936] Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnera…
Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-54547] Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to…
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuthInjectionMiddleware in meta_ads_mcp/core/http_auth_integration.py rejects HTTP MCP requests only when both auth_token and pipeboard_token are absent, while extract_token_from_headers() does not recognize X-Pipeboard-Token as a primary credential. A network caller using the stre…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57134] PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src…
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90840] A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the func…
A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57132] PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled ma…
PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90620] A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.…
A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling rel…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90601] A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the fi…
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90579] A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the func…
A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early th…