Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77248] MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while upload_attachment accepts an unrestricted file_path. An unauthenticated network caller can read files available to the MCP process, upload them to an attacker-select…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94455] An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable withou…
An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on that list, so no authentication runs for these routes. The endpoint's only check is that the request body carries a token bearing a valid signature from the instanc…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65114] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause mi…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75791] Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authenticat…
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94540] DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attacker…
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93559] A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0…
A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The reported GitHub issue was closed automatically due to inactivity.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-58197] ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol s…
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malici…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88259] CareCam CM2507 IP cameras do not require authentication for access to its network video streaming se…
CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54504] MCP Documentation Server is a local-first document management and semantic search server for AI codi…
MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with START_WEB_UI enabled by default and WEB_PORT set to 3080. startWebServer uses app.listen(PORT) without a host, which binds the unauthenticated document-management API…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54446] NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage …
NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-netlicensing-api-key, Authorization: Bearer, and the apikey query parameter pass through ApiKeyMiddleware in src/netlicensing_mcp/server.py without authentication. T…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92972] SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route e…
SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary rank_ip and rank_port values to redirect decode workers to attacker-controlled endpoints, causing denial of service or disclosure of KV transfer metadata including s…
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad alta en Dell OpenManage Server Administrator permite ejecución remota sin autenticación
Dell OpenManage Server Administrator en versiones anteriores a 11.1.0.3 presenta una vulnerabilidad de autenticación faltante (CVSS 8.1) que permite a atacantes remotos ejecutar código sin credenciales. Esta falla afecta infraestructuras de servidores en empresas de México y LATAM que utilizan esta herramienta para gestión de sistemas Dell PowerEdge.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20343] A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remo…
A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker could exploit this vulnerability by repeatedly invoking the API. A successful exploit could allow the attacker to download sensitive files …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92729] SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytic…
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92625] Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. …
Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An unauthenticated remote attacker can call this endpoint repeatedly to hold the service i…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61590] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only `DEBUG`. In the misconfigu…
M Alto vulnerabilidad
16/09/2026
XikeStor Layer3: Falla de autenticación en descarga de configuración (CVE-2026-88263)
Los switches Layer3 de XikeStor carecen de validación de autenticación en el servicio de descarga de datos de configuración, permitiendo a atacantes no autenticados recuperar credenciales y configuraciones de red. Esta exposición es alta en entornos corporativos de LATAM que utilizan estos equipos como infraestructura core, riesgando acceso lateral a sistemas internos y uso como puente de salto hacia redes segmentadas.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88065] `tts-be` is a backend for a timetable selector that aims to help students better choose their class …
`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions prior to 2.1.0 have a Broken Access Control vulnerability across several API endpoints (such as `/api/student/{id}/photo` and `/api/course_unit/{id}/exchange/metadata`). By chaining these unauthenticated endpoints, a remote attacker can use the backend as an open proxy to bypass …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-68070] The affected products are missing authentication for a critical function, which could allow an attac…
The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-81238] Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Cri…
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.