Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86502] In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server a…
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
M Alto vulnerabilidad
07/09/2026
[CVE-2026-79645] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-78480] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80132] ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.…
ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
CVE-2026-86292: Autenticación ausente en SourceCodester Simple Traffic Offense System 1.0
Se detectó una vulnerabilidad de autenticación faltante en SourceCodester Simple Traffic Offense System 1.0 en el archivo saveuser.php (componente User Creation). Un atacante remoto puede manipular el parámetro position para crear usuarios sin credenciales válidas, comprometiendo la integridad de sistemas de gestión de infracciones de tránsito. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo alto para municipalidades y autoridades viales en LATAM que usan esta plataforma.
M Alto vulnerabilidad
06/09/2026
[CVE-2026-86259] OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowin…
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en Bifrost HTTP transport permite ejecución de código remoto sin autenticación
Bifrost HTTP transport anterior a versión 2.0.0 permite a atacantes no autenticados cargar y ejecutar plugins maliciosos a través de POST /api/plugins cuando la autenticación de gestión está deshabilitada (configuración por defecto). El cargador de objetos compartidos descarga archivos desde URLs HTTP y los ejecuta como librerías dinámicas en Go, comprometiendo completamente servidores en infraestructuras altas de LATAM. Afecta especialmente a plataformas de integración y orquestación de datos sin hardening de seguridad.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85702] A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca92…
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-9317] Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that a…
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85671] QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_ba…
QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclos…
M Alto vulnerabilidad
02/09/2026
[CVE-2024-35585] Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84485] APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authe…
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84700] PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the cl…
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84696] Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique comm…
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to read and write controller memory and raw flash, persisting implants across power cycles.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84423] A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file …
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanat…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-18771] Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co…
Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass. This issue affects Talassoft Industrial Management Software: from V4 before V.16.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82919] A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the func…
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-54598] Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpo…
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against the live SQLite database. This issue has been patched in version 4.9.4.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-75133] Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulner…
Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable dump filename based on the database name, a limited random range, and the current…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-66047] ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code…
ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing a weak 32-bit connect token via the ppress_connect_process AJAX handler. Attackers can supply a caller-controlled URL through the file request parameter to trigger silent plugin …