Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96750] MongoDB Compass can interpolate a database name without escaping into the initial input of its embed…
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requi…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96756] orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory gener…
orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-79310] webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be…
webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the attacker can write to and later renders them through the precompiled template loader, the sandbox is bypassed and the attacke…
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad de ejecución de código en Emacs anteriores a versión 31.2 (CVE-2026-96442)
Se identificó una falla alta en Emacs que permite ejecutar código arbitrario a través del modo Flymake cuando se editan archivos no confiables. La vulnerabilidad afecta versiones anteriores a 31.2 y se activa durante la verificación de sintaxis con backends de lenguaje distintos a Lisp, comprometiendo la integridad del usuario que ejecuta Emacs. Desarrolladores y administradores en LATAM que utilizan Emacs en entornos de desarrollo deben aplicar actualizaciones inmediatamente.
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta en plugin WP Ultimate Review permite ejecución arbitraria de shortcodes
El plugin WP Ultimate Review para WordPress (versiones hasta 2.4.2) es vulnerable a ejecución arbitraria de shortcodes debido a validación insuficiente en acciones de usuario. Atacantes autenticados con acceso de suscriptor pueden ejecutar código arbitrario, comprometiendo sitios WordPress comúnmente usados en LATAM para ecommerce, contenido corporativo y aplicaciones altas.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-55071] MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Pri…
MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the equivalent Python API can embed newline characters in the package argumen…
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de inyección de código en DedeCMS hasta versión 5.7.118
Se identificó una vulnerabilidad de inyección de código en DedeCMS versiones hasta 5.7.118, localizada en el archivo plus/mytag_js.php que permite manipulación remota del parámetro 'aid'. El exploit está públicamente disponible y representa un riesgo inmediato para sitios web y portales de contenido en México y Latinoamérica que utilizan este CMS. La vulnerabilidad permite ejecución de código arbitrario con impacto alta en la integridad y disponibilidad de aplicaciones web.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87067] The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instan…
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina…
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución de shortcodes en ProfilePress para WordPress
El plugin ProfilePress para WordPress (versiones hasta 4.17.2) es vulnerable a ejecución arbitraria de shortcodes por usuarios autenticados debido a validación insuficiente antes de ejecutar do_shortcode. Esta vulnerabilidad afecta sitios de e-commerce, formularios de registro y portales de contenido restringido ampliamente utilizados en LATAM. Un atacante autenticado podría inyectar código malicioso que se ejecute en el contexto del sitio WordPress.
M Alto vulnerabilidad
19/09/2026
Ejecución Remota de Código en plugin Welcomizer para WordPress (CVE-2026-4327)
El plugin Welcomizer para WordPress en versiones hasta 2.8.1 permite ejecución remota de código sin autenticación. La vulnerabilidad CVSS 8.8 se debe a verificación insuficiente de permisos en el manejador AJAX 'savesection' combinado con uso de eval(). Afecta directamente a sitios WordPress en México y LATAM que ejecuten este plugin sin parchear.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta en plugin Save as PDF de PDFCrowd para WordPress permite ejecución arbitraria de funciones
El plugin 'Save as PDF Plugin by PDFCrowd' para WordPress (versiones hasta 4.6.1) contiene una vulnerabilidad de invocación arbitraria de funciones a través del atributo shortcode `pdf_created_callback`. La función `eval_shortcode()` no sanitiza ni valida atributos de shortcode, permitiendo a atacantes ejecutar código PHP malicioso en sitios WordPress vulnerables. Esto afecta especialmente a empresas en LATAM que usan este plugin para generar reportes y documentos PDF sin aplicar restricciones de capacidades.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93759] Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instea…
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field value…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61552] Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/obj…
Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an objects/create/* permission can inject Icinga 2 DSL configuration, escape the intended object, create additional objects, and exceed the user's assigned privileges.…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54612] Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor…
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file portion of data-v-save-global to the active theme directory before loadHTMLFile() and file_put_contents() operate on it. An authenticated user with the default Edi…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-15815] Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin arch…
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote cod…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86320] A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources wit…
A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92593] Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controll…
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on …
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92784] @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into gen…
@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that execute in the developer's browser when the Inferencer page renders.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63325] Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version …
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92125] Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTrans…
Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitrary AST transformation at compile time, bypassing the sandbox protection and executing arbitrary code in the context of the Jenkins controller JVM.