Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-92619] The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up t…
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy — bypassi…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81810] The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability…
The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export the site, allowing such a user to import an arbitrary site archive and gain administrator access. Exploitation requires an administrator to have granted the expor…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81445] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Man…
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92958] vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the b…
vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: ['*', '-fs', '-child_process'] }), negative entries are matched by exact module name in lib/builtin.js, so -fs removes only the builtin named fs and does not remove builtin subpaths such as fs/promises. Sandboxed code can there…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81442] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Man…
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-88904] The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST rou…
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85128] The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role reques…
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selec…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55225] Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployme…
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role with full Secret CRUD permissions there and bind it to the Entity Operator Servi…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-65831] ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/…
ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator authorization. GraalPolyglotEngine also permits scripts to bypass the allowedPackages whitelist by reflecting from the bound …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92073] Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1…
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92062] Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, …
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92055] Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Fire…
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92053] Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox…
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92047] Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 a…
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92033] Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.
Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92015] Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Fi…
Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92017] Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox …
Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-14805] The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and incl…
The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in adm…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-75983] The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is v…
The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap` filter and unconditionally returning the always-true `'exist'` primitive for every c…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90856] A security vulnerability has been detected in SourceCodester College Notes Gallery Management System…
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.