Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
CVE-2026-86292: Autenticación ausente en SourceCodester Simple Traffic Offense System 1.0
Se detectó una vulnerabilidad de autenticación faltante en SourceCodester Simple Traffic Offense System 1.0 en el archivo saveuser.php (componente User Creation). Un atacante remoto puede manipular el parámetro position para crear usuarios sin credenciales válidas, comprometiendo la integridad de sistemas de gestión de infracciones de tránsito. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo alto para municipalidades y autoridades viales en LATAM que usan esta plataforma.
M Alto vulnerabilidad
06/09/2026
[CVE-2026-86214] A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown functio…
A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, n…
M Alto vulnerabilidad
06/09/2026
[CVE-2026-18056] The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the acc…
The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without p…
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de omisión de autenticación en Coolify hasta v4.3.17
Coolify versiones anteriores a 4.3.17 contiene una falla de autenticación en el manejador de callback OAuth que permite a atacantes registrar direcciones de correo de víctimas en proveedores OAuth habilitados para obtener acceso autenticado sin verificar identidades ni requerir contraseña. Empresas que usan Coolify como plataforma de infraestructura o despliegue en México y LATAM corren riesgo de compromiso de cuentas administrativas y acceso no autorizado a recursos altas.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85702] A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca92…
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-18221] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improp…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-83961] ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege es…
ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-82183] The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion retur…
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-12526] The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the reques…
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing ad…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84423] A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file …
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanat…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19806] The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin …
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit `…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82919] A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the func…
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-61641] Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before …
Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverifi…
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta de elusión de autenticación en plugin SAML SSO para WordPress (CVE-2026-75807)
El plugin SAML Single Sign On – SSO Login para WordPress (versiones ≤5.4.6) contiene una vulnerabilidad de elusión de autenticación que permite a atacantes validar certificados X.509 antes de completar la verificación de firma en la respuesta SAML. En LATAM, donde muchas empresas integran WordPress con sistemas de identidad corporativa SAML, esta falla expone credenciales y acceso no autorizado a portales internos, clientes y plataformas e-commerce.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta de elusión de autenticación en Rodauth anterior a 2.46.0
Rodauth versiones anteriores a 2.46.0 contiene una vulnerabilidad de elusión de autenticación en la ruta webauthn_login que permite a usuarios autenticados suplantarse como otras cuentas. El defecto reside en la lógica impropia de resolución de cuentas que utiliza identificadores de sesión en lugar de validar correctamente el vínculo de credenciales, exponiendo sistemas que dependen de WebAuthn en México y LATAM a compromisos de cuentas no autorizados.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76548] The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end fil…
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-17203] IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain …
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18891] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and a…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-73208] An attacker that holds a token intended for a different purpose can authenticate, because when an OA…
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be acc…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81202] A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function creat…
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.