Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-76801] The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin fo…
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a trivially bypassable regex blacklist in Executer::allowedToRun() that fails to block WordPress core functions such as wp_insert_user, update_option, and file_put_c…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-58846] In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check…
In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-58874] In multiple functions of SmsController.java, there is a possible escalation of privilege due to a mi…
In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-66818] Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over…
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en hawtio-operator: acceso no autorizado a Secretos del cluster
Se identificó una falla en hawtio-operator que permite al operador acceder a todos los Secretos del cluster mediante permisos excesivos en ClusterRole (create, get, list, update, watch). El compromiso del pod del operador exponendría credenciales y tokens en todos los namespaces, afectando la seguridad de infraestructuras Kubernetes en producción en México y LATAM. El riesgo es alta (CVSS 8.2) para empresas que despliegan este operador en plataformas cloud o on-premises.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80166] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-14444] The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to…
The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, and who possess the access_key, to create a new u…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/09/2026
Vulnerabilidad alta en SureCart (WordPress) permite escalada de privilegios y takeover de cuentas
El plugin SureCart para WordPress en versiones anteriores a 4.6.3 contiene una falla de validación que permite a usuarios con permisos de suscriptor modificar direcciones de correo de otros usuarios, incluidos administradores, y tomar control de sus cuentas mediante reset de contraseña. Esta vulnerabilidad afecta directamente a tiendas en línea y plataformas de comercio electrónico operadas en México y Latinoamérica que usan este plugin.
M Alto vulnerabilidad
05/09/2026
Escalación de privilegios alta en plugin Abandoned Cart Pro para WooCommerce
El plugin Abandoned Cart Pro para WordPress contiene una vulnerabilidad de escalación de privilegios (CVSS 8.8) que afecta todas las versiones hasta la 10.7.1. Usuarios autenticados pueden ejecutar acciones administrativas sin verificación de capacidades o nonces, comprometiendo tiendas de comercio electrónico en la región. La vulnerabilidad impacta acciones AJAX altas de configuración y envío de correos, exponiendo datos sensibles de clientes y carros abandonados.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-80467] The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role subm…
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19453] The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the acco…
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84115] A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown functio…
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 i…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79744] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no authorization check. It is protected only by the app-wide authentication middleware and a rate limiter — it never inspects req.user.…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82807] A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown …
A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82628] A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function …
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-79996] The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability chec…
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-19423] The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection whe…
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant thems…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-13415] The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing se…
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administra…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-75977] The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Coo…
The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_a…