Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90524] A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a…
A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a ro…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90504] A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae8641105…
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. T…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-89080] The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated reques…
The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-71416] Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, th…
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88895] CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attack…
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-77771] The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not scope its second-factor attempt limit to the account being attacked, keying it instead to an identifier the client supplies and can change at will, allowing an attacker who already knows a victim's password to make unlimited one-time-passcode guesses and defeat the second factor. A second valid…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87922] A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9…
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing authentication. The attack may be performed from remote. The exploit has been rele…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87016] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 un…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to SQL LIKE substring matching on SQLite. An OAuth subject containing percent or underscore wildcard characters could resolve to a different stored ident…
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad de autenticación en Parse Server <= 8.6.87 y 9.0.0-9.10.1 (CVE-2026-87806)
Parse Server contiene un bypass de autenticación en su adaptador LDAP integrado que permite a atacantes autenticarse sin credenciales válidas. El servicio acepta respuestas sin errores del directorio incluso cuando no se proporciona contraseña. Empresas en LATAM que usan Parse Server con LDAP en producción (principalmente startups y plataformas de datos) enfrentan riesgo alta de acceso no autorizado a sistemas y datos sensibles.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80099] Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because th…
Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request — performs an HMAC-style Bearer token comparison that degenerates when `HiiveConnection::g…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-76009] The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication By…
The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86808] A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected elem…
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86810] A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function…
A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version 1.10.0 is sufficient to resolve this issue. The patch is named 6fc91c49eebdb8bfdfe…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86669] A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login …
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not re…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-80097] Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privil…
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86721] AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cook…
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86722] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vul…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86723] AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerabil…
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86306] A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601…
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made availab…
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad de autenticación impropia en Tenda AC9 15.03.05.14 (CVE-2026-86300)
Se identificó un fallo en el manejador R7WebsSecurityHandler del componente de gestión web en routers Tenda AC9 versión 15.03.05.14 que permite eludir autenticación de forma remota. Esta vulnerabilidad de CVSS 7.3 afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos dispositivos en redes corporativas. El exploit ya está público, aumentando significativamente el riesgo de explotación.