Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-59160] Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-gra…
Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in packages/turbo-graph-ui/app/api/run/route.ts has no authentication, authorization, CSRF protection, or task allowlist. The…
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad de acceso anónimo en lamp-cloud permite lectura de propiedades del sistema JVM
lamp-cloud en versiones hasta 5.10.0 expone un patrón de ruta /*/anno/** accesible sin autenticación, permitiendo a atacantes remotos recuperar propiedades altas del JVM como rutas del sistema de archivos, classpath, detalles del SO y secretos de inicio mediante solicitudes POST a /defGenProject/anno/getProperties. Esta exposición de metadatos del servidor facilita reconocimiento para ataques posteriores contra infraestructura en México y LATAM.
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad alta en PraisonAI permite ataques de DNS rebinding en sistemas locales
PraisonAI (versiones 0.6.0 a 1.6.59 en praisonaiagents y 3.10.0 a 4.6.59 en PraisonAI) expone endpoints legados /sse y /messages/ sin validación de Host, Origin ni autenticación, permitiendo que sitios maliciosos ejecuten ataques de DNS rebinding contra instancias locales. Afecta especialmente a empresas que ejecutan sistemas multi-agente en infraestructura interna o en la nube privada. El CVSS de 8.3 refleja alto riesgo de compromiso de datos y control remoto.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-53714] Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based…
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deploy.type=GatewayNamespace, installs a JWT StreamInterceptor but no UnaryInterceptor, leaving every unary Fetch RPC unauthenticated. The streaming interceptor also au…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90944] Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication,…
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90938] LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server…
LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by the upstream repository, Docker image, or docker-compose (which additionally publishes port 5401 to the host); the key check is therefore skipped entirely. Any remot…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90620] A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.…
A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling rel…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90579] A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the func…
A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early th…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90524] A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a…
A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a ro…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90504] A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae8641105…
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. T…
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de lectura de archivos sin autenticación en WWBN AVideo (CVE-2026-89250)
WWBN AVideo contiene una vulnerabilidad de lectura de archivos sin autenticación en el endpoint getRecordedFile.php que expone archivos de video grabados en FLV desde el directorio temporal. Atacantes pueden descargar archivos de video en vivo sin validación de autenticación utilizando claves de stream conocidas o adivinadas. Este riesgo afecta principalmente a plataformas de streaming y educación en línea en LATAM que utilizan esta solución para transmisiones en vivo.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de autenticación en WeenyGenius (CVE-2026-89176)
WeenyGenius, sistema de gestión de laboratorios informáticos de Howyar Technologies, presenta una vulnerabilidad de autenticación faltante (CVSS 8.8) que permite a atacantes en la misma red suplantar identidades de estudiantes o docentes sin credenciales. La suplantación de maestros compromete el control remoto de equipos estudiantiles, mientras que la de estudiantes interrumpe operaciones académicas normales. Instituciones educativas en México y LATAM con este software están expuestas en infraestructuras de redes cerradas o híbridas.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-49363] An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node detai…
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-49362] An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leadin…
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87922] A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9…
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing authentication. The attack may be performed from remote. The exploit has been rele…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-77974] After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the …
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86808] A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected elem…
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69528] Missing authentication for critical function in Windows Shell allows an authorized attacker to eleva…
Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86727] AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php t…
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming creden…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86728] AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php…
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.