Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
04/09/2026
[CVE-2026-16281] The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can ed…
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85378] A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601…
A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is pub…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-69857] Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to…
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84836] Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.
Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping
M Alto vulnerabilidad
03/09/2026
[CVE-2026-75035] A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector nami…
A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch every other user's tokens, disclosing token metadata and the stored salted hash of the bearer token. This issue affec…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85211] Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects …
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85214] vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users …
vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85182] vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to t…
vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85178] Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKey…
Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider credentials for other tenants, including plaintext OpenAI, Anthropic, and Bedrock API key…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-71404] A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name f…
A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules without verifying ownership. A user with delegated GlobalRole create or update permission could point the annotation at any existing ClusterRole, such as `cluster-admin`, and revoke the permission…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-75033] A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on …
A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced project belonged to the same downstream cluster. A user able to create namespaces on one cluster could set the annotation to a project ID from another cluster and have that project's secrets copied into a namespace und…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85105] A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _s…
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argument session_id causes authorization bypass. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84672] Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra …
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta en Craft CMS: bypass de scope de sitios en mutaciones GraphQL
Craft CMS versiones anteriores a 5.10.11 contienen una vulnerabilidad que permite a atacantes con tokens limitados a un sitio acceder, modificar o eliminar entradas en otros sitios no autorizados mediante bypass de validación en resolvers GraphQL. Esta falla afecta directamente a agencias digitales y empresas que alojan múltiples proyectos en instancias compartidas de Craft CMS en LATAM.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81892] EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 an…
EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed controller based on the routeName query parameter on the kernel.controller event. The swap happens after Symfony's security …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-72001] Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated a…
Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint that omits the expected resource identifier from the token verification call. Attackers holding a single valid share link for any resource can authenticate against ar…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79750] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to servers they own (list views and config edits enforce ownership), but the tool-execution API does not. Any authenticated non-admin user can invoke tools on MCP servers owned by othe…
M Alto vulnerabilidad
31/08/2026
Vulnerabilidad de escalada de privilegios en ToolJet Database anterior a v3.16.44
ToolJet Database versiones anteriores a v3.16.44 contienen una vulnerabilidad de escalada de privilegios en el endpoint join_tables que otorga capacidades JOIN_TABLES a todos los usuarios autenticados sin validar rol o pertenencia al workspace. Atacantes pueden leer tablas arbitrarias de cualquier workspace en ToolJet Database suministrando identificadores de workspace víctima en la ruta de solicitud mientras se autentican con su propio workspace.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82621] A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4c…
A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component Administrative Servlet. Executing a manipulation of the argument action can lead to authorization bypass. It is possible to launch the attack remotely. The exploit has been made …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18904] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.