Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47552] NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unpri…
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47493] NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a…
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100266] In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbit…
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97197] Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
Unauthenticated Broken Access Control in WordPress Backup & Migration
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96817] Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
Subscriber Broken Access Control in MakeCommerce for WooCommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96818] Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versi…
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments)
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96823] Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96348] Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
Unauthenticated Broken Access Control in Bookly
M Alto vulnerabilidad
30/09/2026
[CVE-2026-95587] Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
Unauthenticated Broken Access Control in Hostinger Migrator
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94499] Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
Subscriber Broken Access Control in FormGent
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94120] Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de Autorización en Qorela DC de Interprobe permite Escalada de Privilegios
Una vulnerabilidad de autorización faltante en Qorela DC (versiones 1.6.1-RC29 anteriores a 1.6.2) permite a usuarios autenticados elevar sus privilegios sin autorización adecuada. Afecta infraestructuras de centros de datos en México y Latinoamérica que utilicen esta plataforma de gestión. El CVSS 8.8 indica riesgo alta para la confidencialidad e integridad de sistemas altas.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización en REBUILD hasta v4.4.11 permite acceso no autorizado remoto
Se ha identificado una falla de seguridad en REBUILD versiones hasta 4.4.11 que afecta el módulo /commons/file-editor-save, permitiendo omitir controles de autorización mediante manipulación de parámetros (url/fileKey). Esta vulnerabilidad de severidad alta (CVSS 7.3) puede ser explotada remotamente y su código de ataque ya es público. Empresas en LATAM que usan REBUILD para gestión de contenidos están expuestas a acceso no autorizado a archivos sensibles.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-96896] The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perfor…
The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing users with a subsite administrator role on a multisite network to write and delete arbitrary files in the network's shared filesystem, which can lead to remote code execution.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100744] A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function…
A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 4.2.0 is sufficient to fix this issue.…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100617] Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the org…
Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped permissions such as channel.promote_bundle to users outside the organization.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100608] Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server …
Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and !isCloud()), the /admin/queues mount is protected only by the verifyTokenForBullMQDashboard middleware, which validates the JWT but performs no role, permission, or workspace/organizati…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100605] Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow …
Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts, model responses, and delete messages.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-96532] The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership ch…
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta de autorización en OpenClaw anterior a 2026.7.1
OpenClaw versiones anteriores a 2026.7.1 presentan un fallo de autorización que permite a usuarios no-propietarios ejecutar cambios de configuración MCP mediante los comandos /mcp set y /mcp unset. Los atacantes pueden persistir comandos MCP arbitrarios en stdio que se ejecutan con los privilegios del proceso OpenClaw, comprometiendo la confidencialidad, integridad y disponibilidad del host. Este riesgo afecta principalmente a empresas en LATAM que utilizan OpenClaw en entornos de producción sin restricciones de acceso adecuadas.