Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82641] keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces with…
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en Documenso: carga de PDF sin autenticación en endpoint /api/files/upload-pdf
Documenso versiones anteriores a 2.13.0 permite la carga de archivos PDF sin requerir autenticación en el endpoint /api/files/upload-pdf. Atacantes no autenticados pueden subir PDFs arbitrarios indefinidamente, agotando recursos de almacenamiento y saturando bases de datos con registros huérfanos. Esta vulnerabilidad afecta principalmente a empresas mexicanas y latinoamericanas que utilizan Documenso para gestión de documentos digitales y flujos de firma electrónica.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en KubeEdge CloudCore 1.23.1 permite falsificación de estado de actualización de nodos
KubeEdge CloudCore versiones hasta 1.23.1 acepta reportes de estado de tareas sin autenticación en puerto 10002, permitiendo a atacantes modificar el estado de trabajos de upgrade. Esto compromete la integridad del plano de control en infraestructuras edge/IoT, siendo alta para organizaciones en LATAM con despliegues en manufactura, utilities y telecomunicaciones que dependen de orquestación automática de actualizaciones.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82282] Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticat…
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials. Attackers can observe or intercept the GitHub redirect during setup to obtain the RSA private key and webhook secret, enabling installation token minting and webhook payload forgery.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-77977] Ebyte gateway product's vendor configuration utility does not require authentication before allowin…
Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-76639] Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerabilit…
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-76640] Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT serv…
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE w…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-80208] APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in Interna…
APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies every /api request to the backend server, so both endpoints are reachable by any unauthenticated cli…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81202] A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function creat…
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65105] NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote att…
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55571] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":...}` frame when login_required, permission_required, or a redirecting on_mount hook denies a LiveView mount, but returns without closing the WebSocket or clearing self.view_instance. A browser follows the redi…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55539] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable caller can submit jobs, read results, cancel runs, or delete jobs using operator credentials. The fix adds PRAISONAI_JOBS_API_KEY middleware for Authorization or X-API-Key. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55533] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows …
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run requests despite authentication being enabled. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55534] PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents …
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even when an API key was supplied. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55538] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses co…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or incorrect bearer and X-API-Key values still reach agent execution. This issue is fixed in version 4.6.58.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55528] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes Server…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is configured. This issue is fixed in version 1.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-67578] FA-50 all versions miss authentication for some configuration. An attacker with access to the vesse…
FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78154] A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function…
A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user_invitation_code.py of the component Public Invitation-Code Redemption Endpoint. The manipulation of the argument code leads to missing authentication. Remote exploitation of the attack is possible. The project was informed of the pro…
M Alto vulnerabilidad
22/08/2026
[CVE-2026-59808] AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEn…
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with upload permission can retrieve an administrator's video_id_hash by omitting the v…
M Alto vulnerabilidad
21/08/2026
Vulnerabilidad alta de bypass de autenticación en Combodo iTop anterior a v3.2.3
Combodo iTop, herramienta web de gestión de servicios de TI, contiene una vulnerabilidad de bypass de autenticación (CVSS 8.6) que permite a atacantes no autenticados ejecutar archivos PHP arbitrarios desde el directorio env-production en instancias nuevas. Afecta altas funciones de ITSM en empresas LATAM. La vulnerabilidad se ha corregido en versión 3.2.3.