Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76087] Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous form…
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete submission without session binding, ownership validation, or a valid submissionEditToken. An unauthenticated attacker can enumerate sequential IDs and overwrite or hij…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76089] Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-no…
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs an…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-55610] InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create profe…
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's multi-company installations, any user who is an Owner of one company can read and overwrite any user account in any other company on the same installation. `GET/PUT /api/v1/users/{user}` resolves the target `User` by global pr…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86678] ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user t…
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad de Control de Acceso en ManageEngine OpManager y Firewall Analyzer (CVE-2026-84791)
ManageEngine OpManager y Firewall Analyzer versiones 12.8.710 e inferiores contienen una vulnerabilidad de control de acceso deficiente (CVSS 7.1) que permite a usuarios autenticados con privilegios bajos modificar configuraciones de reportes de Change Management en firewalls fuera de su alcance asignado. Esto afecta directamente a empresas en México y LATAM que utilizan estas soluciones para gestión de infraestructura de red y firewall. El riesgo se incrementa en organizaciones con múltiples equipos de operaciones sin segmentación adecuada de permisos.
M Alto vulnerabilidad
23/09/2026
Control de acceso roto en ManageEngine OpManager y Firewall Analyzer versión 12.8.710 y anteriores
ZohoCorp ManageEngine OpManager y Firewall Analyzer versiones 12.8.710 e inferiores contienen una vulnerabilidad de control de acceso deficiente (CVSS 7.1) que permite a usuarios autenticados con permisos bajos crear notificaciones de alertas para firewalls fuera de su ámbito asignado. Afecta principalmente a empresas con infraestructura distribuida en LATAM que dependen de estas herramientas de monitoreo de red. El riesgo incluye exposición de configuraciones altas, desviación de alertas de seguridad y movimiento lateral no autorizado.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96271] Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mut…
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94462] Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5…
Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate a cart by prefixed_id but does not require a cart token or otherwise verify possession of the selected guest cart. An authenticated customer can derive reversible …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95655] Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowi…
Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94534] lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/av…
lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including nickname, ID card, sex, nation, education, work description, and avatar attachments of other users.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94535] lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpo…
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-77523] MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model pa…
MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads and saves a Model by id alone without including workspace_id in the query. An authenticated user with model read permission in an attacker-controlled workspace can supply a known victim model_id to read or overwri…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94497] jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints ac…
jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-48826] HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend…
HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a grou…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-48975] HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Upd…
HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's active group. An authenticated low-privileged user who knows or enumerates anothe…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/09/2026
[CVE-2026-48976] HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in b…
HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier UUID to PUT /v1/notifiers/{id} can read the returned stored url, which may contai…
M Alto vulnerabilidad
19/09/2026
[CVE-2026-93991] Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArc…
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-62279] LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Pr…
LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming destination vehicleIds the user could edit. The endpoint authorized the destination vehicles but fetched source records in Controllers/VehicleController.cs withou…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93758] An insecure direct object reference in the nested attributes handling of the Mongoid object-document…
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This ma…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-12384] Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allo…
Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.