Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de control de acceso en NL Portal Backend Libraries permite acceso no autorizado a tareas
El paquete `nl.nl-portal:taak` (versiones 1.5.0 a 3.0.0) no valida correctamente la propiedad de tareas en la mutación GraphQL `submitTaakV2`, permitiendo a usuarios autenticados leer formularios de otros usuarios si conocen o adivinan su ID de tarea. Esta vulnerabilidad afecta sistemas de gobierno digital en portales de atención ciudadana que procesan información sensible de residentes, clientes y proveedores.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89262] MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint…
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-80434] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulat…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81210] IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String…
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data ro…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88865] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership …
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, or RTMP destinations.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-80354] Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorizatio…
Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79324] Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/mo…
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-19651] IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an att…
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78462] Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attack…
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86725] AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerabili…
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored access_token and refresh_token, then delete the compromised record to destroy the victim…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86720] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of l…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, Facebook, …
M Alto vulnerabilidad
07/09/2026
Bypass de autorización alta en SourceCodester Syllabus-Aligned LMS 1.0 (CVE-2026-86277)
Se ha identificado una vulnerabilidad de bypass de autorización en SourceCodester Syllabus-Aligned Learning Management & Examination System versión 1.0, específicamente en el archivo delete_exam.php. Un atacante remoto puede manipular el parámetro ID para eludir controles de acceso y eliminar exámenes sin autorización. La vulnerabilidad con CVSS 7.3 afecta instituciones educativas en LATAM que utilizan este LMS para gestión académica y evaluaciones.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86263] A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. …
A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now publi…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86261] A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8…
A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to authorization bypass. The attack can be executed remotely. The exploit has been made …
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86262] A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d6…
A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument userID/id leads to authorization bypass. The attack is possible to be carried out rem…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85638] A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/us…
A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85607] Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (mess…
Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they query the database by caller-supplied conversation or message ID without verifying…
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de omisión de autorización en Snipe-IT anterior a v8.6.2 afecta gestión de activos
Snipe-IT versiones anteriores a 8.6.2 contienen una falla de autorización en reportes de aceptación de checkout cuando está habilitado el soporte multi-empresa. Usuarios autenticados con permiso reports.view pueden enumerar IDs secuenciales, eliminar o enviar recordatorios de aceptaciones de otras empresas, comprometiendo la integridad de datos de auditoría y control de activos en organizaciones con múltiples sucursales en LATAM.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de omisión de autorización en snipe-it anterior a 8.6.3 afecta gestión de usuarios
snipe-it versiones anteriores a 8.6.3 contienen una vulnerabilidad de omisión de autorización en la funcionalidad de eliminación masiva que permite a usuarios restringidos eliminar de forma reversible usuarios fuera de su alcance autorizado. Los atacantes pueden incluir IDs de usuario no autorizados en solicitudes de eliminación masiva para eludir restricciones a nivel de instancia y modificar o desactivar cuentas que no deberían poder acceder. Esta vulnerabilidad afecta directamente a empresas LATAM que utilizan snipe-it para gestión de inventario de TI.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-16281] The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can ed…
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.