Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90787] A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189…
A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow. Such manipulation of the argument level leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might b…
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta en Parallels Desktop: escalada de privilegios local vía socket mundial
Parallels Desktop ejecuta el servicio prl_disp_service con permisos root a través de un socket accesible mundialmente (/var/run/prl_disp_service.socket), permitiendo a usuarios locales ejecutar comandos arbitrarios sin validación de firma ni pertenencia a grupos administrativos. La vulnerabilidad afecta principalmente a empresas en México y LATAM que usan Parallels Desktop en infraestructuras de desarrollo, testing y virtualización en macOS, exponiendo sistemas con múltiples usuarios o acceso compartido.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90523] A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eef…
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-86406] The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of t…
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged ro…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-80071] The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may…
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-15451] The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in ver…
The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-lev…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87759] The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check…
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/09/2026
[CVE-2026-77752] The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user req…
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promo…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-74925] The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capab…
The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-87958] IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where …
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-75777] IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container p…
IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88891] OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing …
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88863] capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank aga…
capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles permission for org_super_admin invitations, so an authenticated user holding only the o…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84042] A flaw was found in crun. When crun is built with libkrun and a container is started rootful with pa…
A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81431] The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form …
The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can therefore register a new account with an arbitrary role, including Administrator, leadi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87998] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 un…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned external connection without a separate administrator check or a check for other dependent knowledge bases. A non-adminis…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-14359] The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in …
The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and using parse_str() + extract() to import attacker-controlled variables from $_POST['pa…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-75927] The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus…
The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15 `manage_capabilities_*` capabilities — including `manage_capabilities`, `manage_capabilities…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-17553] The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and in…
The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX handler iterating over every $_POST key and passing it directly into update_option() without any allowlist, while gating the handler only on 'manage_options' OR the plugin's custom 'wpec_manager' capability. The plugin's bui…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-76801] The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin fo…
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to block WordPress core functions such as wp_insert_user, update_option, and file_put_c…