Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
05/09/2026
[CVE-2026-19887] The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chose…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-61686] SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveCompon…
SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can supply an arbitrary PHP serialized payload. Version 3.0.1 fixes the issue.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84752] Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.
Contributor PHP Object Injection in RTMKit
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84670] Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can b…
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84647] In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.5…
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field …
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84650] In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from dese…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
M Alto vulnerabilidad
02/09/2026
Inyección de objetos PHP sin autenticación en Ninja Forms - Layout & Styles ≤ 3.0.31
Se ha identificado una vulnerabilidad alta de inyección de objetos PHP sin autenticación en el plugin Ninja Forms - Layout & Styles en versiones 3.0.31 y anteriores. Los atacantes pueden explotar esta falla para ejecutar código malicioso en servidores web, afectando principalmente a sitios WordPress en México y LATAM que utilizan este complemento. La vulnerabilidad tiene un score CVSS de 8.8, indicando riesgo alta de comprometimiento de integridad y disponibilidad.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81283] Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
Subscriber PHP Object Injection in WP User Frontend
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19116] The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from b…
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code execution when a suitable gadget chain is present on the site.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-71981] Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attacker…
Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout handler. Attackers can pass a base64-encoded serialized payload through this parameter, which is decoded and passed directly to unserialize() without an allow-list, …
M Alto vulnerabilidad
01/09/2026
[CVE-2026-72649] Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead…
Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended. Exploitation requires an authenticated user with sufficient privileges to create and de…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84202] ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary c…
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61775] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61776] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61777] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61778] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61779] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61773] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61774] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61769] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.