Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta en ESPnet permite ejecución arbitraria de código en modelos entrenados
ESPnet anterior a versión 202609 deserializa puntos de control de modelos preentrenados usando torch.load sin validación (weights_only=False), permitiendo ejecución de código arbitrario desde archivos maliciosos. Atacantes pueden crear archivos de punto de control comprometidos que ejecutan código durante la carga en procesos de inicialización o ajuste fino, comprometiendo sistemas de procesamiento de voz e IA en empresas LATAM que dependan de esta librería.
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inyección de objetos PHP en plugin Tutor LMS para WordPress
El plugin Tutor LMS (versiones ≤4.0.7) contiene una vulnerabilidad de inyección de objetos PHP en el manejador AJAX `tutor_save_withdraw_account` que permite a atacantes no autenticados ejecutar código mediante el parámetro `withdraw_method_field`. Afecta principalmente a plataformas de educación en línea y cursos corporativos en LATAM que dependen de este plugin en WordPress. El riesgo es alta (CVSS 8.8) al carecer de validación de capacidades/roles, confiando solo en nonce.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-84099] The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a …
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62107] Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
Unauthenticated PHP Object Injection in Masteriyo - LMS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-73699] FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated atta…
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81784] Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
Unauthenticated PHP Object Injection in Wise Chat
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82925] The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized…
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such insta…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87874] A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although…
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a n…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87930] MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, …
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.
M Alto vulnerabilidad
09/09/2026
[CVE-2024-58381] PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processin…
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81385] Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to e…
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77484] Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a…
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69694] Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authoriz…
Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-65772] Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute…
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-47297] Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over…
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-12648] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-12651] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en Live Composer para WordPress permite inyección de objetos PHP
El plugin Live Composer (versiones hasta 2.1.18) en WordPress es vulnerable a inyección de objetos PHP mediante deserialización de datos no confiables. Atacantes autenticados con acceso de colaborador pueden explotar esta falla para ejecutar código malicioso. Afecta especialmente a sitios pequeños y medianos en LATAM que usan este constructor visual sin actualizar regularmente.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-76967] SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally…
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This res…
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad alta en Artemis de EAP: deserialización insegura por defecto
EAP's Artemis permite deserialización de objetos sin validación de seguridad por defecto, exponiendo servidores a ejecución remota de código malicioso. El método ObjectMessage.getObject() utiliza ObjectInputStreamWithClassLoader con listas de permitidos/bloqueados vacías, lo que acepta cualquier clase. Empresas en LATAM con infraestructura Java en producción enfrentan riesgo alta de compromiso de sistemas.