Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,046
Total alertas
3206
Críticas
10568
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
01/07/2026
[CVE-2026-53903] MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servl…
MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement endpoint. The application does not properly validate whether an authenticated user is authorized to access a requested document, allowing direct retrieval based on a user-supplied identifier. An attacker can access trading documents belonging to other…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-53904] MCO is vulnerable to Account Denial of Service due to improper implementation of password reset func…
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as well as previously issued temporary passwords, furthermore, password resets are not limited in any way. An attacker who provides victim's email and answer to their security question, can successfully initiate the reset pro…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-53905] MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hi…
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks. This may expose sensitive permission mappings and internal configuration details. Because vendor contact attempts were unsuccessfu…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-53906] MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to da…
MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the filename parameter allows writing files to arbitrary locations as well as indirect disclosure of absolute server paths through error messages. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.…
F Alto vulnerabilidad
01/07/2026
[CVE-2026-14181] @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the st…
@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed percent-encoded sequences. Inputs such as an incomplete percent escape or a truncated multibyte sequence cause the underlying decoder to throw synchronously, and the exception escapes the middie normalize step and terminates the Node.js p…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-13228] The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerab…
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.6.3 This is due to an Insecure Direct Object Reference (IDOR) in the create_or_update() function of OsOrdersController, which allows an authenticated Agent to supply an arbitrary order[customer_id] and overwrite any Late…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-12142] The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cro…
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/07/2026
[CVE-2026-12575] DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.
DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-12576] DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Chann…
DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-50043] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product with an administrative privilege.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-10538] Messaging consumer functionality allows deserialization of user-controlled data without sufficient r…
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-12158] The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-S…
The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible for unauthenticated attackers to escalate the privileges of an arbitrary form submitter to administrator by creating a malic…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-12224] The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities RES…
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5.0.4. This is due to the `update_capabilities()` REST handler accepting arbitrary capability strings from the request body and passing them directly to WP_User::add_cap() with no allowlist validation, only verifying that the caller holds the dokanda…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-11568] The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authoris…
The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option pricing/SKUs) of private and draft, non-public products by supplying the product ID. Wor…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-11794] The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not re…
The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it creates a user from a public form submission, allowing unauthenticated visitors to create an administrator account when an active integration maps the user role to a public form field. This requires a specific, non-default multi-Advanced Form Integration — …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/07/2026
[CVE-2026-11823] The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the…
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is interpolated verbatim into a SQL LIKE clause without use of $wpdb->prepare() or any …
M Alto vulnerabilidad
01/07/2026
[CVE-2026-11883] The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the s…
The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an attacker who already knows a user's password to bypass the two-factor authentication requirement by submitting a malformed request.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-12579] AS228T with Authentication Bypass Vulnerability
AS228T with Authentication Bypass Vulnerability
M Alto vulnerabilidad
01/07/2026
[CVE-2026-14193] DVP80ES300T with Improper Validation of Array Index Vulnerability
DVP80ES300T with Improper Validation of Array Index Vulnerability
M Alto vulnerabilidad
01/07/2026
[CVE-2026-1239] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to…
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.