Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-69148] MLflow is an open source AI engineering platform for agents, large language models, and machine lear…
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated users to create a model version that references another user's artifact directory…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75109] Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the…
Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads by terminating, pausing, or unpausing tasks they do not own.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-54356] Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/u…
Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values and obtain signedUrl and publicUrl values backed by stored S3 datasource credentia…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-9771] The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On bu…
The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode caller. Prior to the fix it validated only the output buffer (K_SYSCALL_MEMORY_WRITE) and passed the two struct device * arguments, src_dev and dst_dev, directly into the implementation without any obj…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75051] In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was po…
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75044] In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allow…
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16471] Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun…
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16467] Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F…
Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-74869] stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message hand…
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message with an arbitrary server ID, receiving live UserUpdate events including display n…
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad alta de evasión de autorización en WP Travel Engine (CVE-2026-17087)
El plugin WP Travel Engine para WordPress (versiones ≤6.8.4) permite a atacantes no autenticados acceder a datos privados de reservas y facturación de clientes mediante evasión de controles de autorización. Esta vulnerabilidad afecta directamente a agencias de viajes, operadores turísticos y plataformas de booking en LATAM que utilizan este plugin para gestionar reservaciones y pagos.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-16772] In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to …
In Akaunting versions sync()` call without verifying whether the caller is authorized to manage roles. …
M Alto vulnerabilidad
14/08/2026
Plugin Grav API: bypas de restricción de scopes en endpoint de reportes (CVE-2026-72825)
El plugin getgrav/grav-plugin-api anterior a versión 1.0.13 contiene una vulnerabilidad que permite eludir las restricciones de scope de API keys. Un atacante con credenciales de API limitadas puede ejecutar operaciones de configuración a nivel administrador en el endpoint POST /reports/twig-content/allowlist, comprometiendo la integridad de sistemas Grav en producción. Afecta especialmente a plataformas de contenido desplegadas en México y LATAM que exponen APIs internas.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-72810] SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast…
SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receive unfiltered edits. Attackers can establish a WebSocket connection to the publish surface and passively receive real-time content events including password-protected and forbidden documents without authentication.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73658] Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4…
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname, while apps/webapp/app/routes/api.v1.packets.$.ts accepts params["*"] without rejecting dot segments and uses findResourc…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73305] Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign cal…
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An app-scoped builder could scope the request to an app they control and then grant themselves builder access or an arbitrary role in another app, expos…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72675] Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unautho…
Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its Elasticsearch operations with elevated internal permissions and relies on a per-request space filter to keep the machine learning data of one space separated from another. Part of the Machine Learning fu…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72665] Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic …
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live que…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72669] The state that Kibana stores for an Observability Onboarding flow is not bound to the user who creat…
The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticated user who holds only generic read access to the space can therefore discover the onboarding flows of other users, read their onboarding state, and write arbitrary progress data into them. A tampered …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59714] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 bef…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_chann…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66469] Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.
Unauthenticated Broken Access Control in Arvow AI SEO Writer