Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82432] Description Nimbus validated `topology.blobstore.map` against the calling subject at submission tim…
Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validation, so a caller authorised to rebalance a topology could introduce a blobstore map entry naming a blob whose ACL does not grant them access. Supervisors localise …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-73236] Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks…
Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with the same string cannot be correctly distinguished, resulting in incorrect authorization. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, fro…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90929] File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-…
File Browser versions >= 2.5.0 and
M Alto vulnerabilidad
14/09/2026
[CVE-2026-72524] Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privile…
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
M Alto vulnerabilidad
14/09/2026
[CVE-2023-50461] An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The …
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend u…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89013] Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthentica…
Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining acc…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78134] strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins bec…
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-75624] IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a …
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-87090] Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write pat…
Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node name may exploit this issue if they can obtain the node ID of a node they do not control. This vulnerab…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88939] knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, a…
knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88862] Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing…
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the authenticating key's user_id, while hasLimitedRbacSubkeyScope() accepts any key with a non-org…
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad de omisión de autorización en Countly Server DBViewer (CVE-2026-87803)
Existe una vulnerabilidad de bypass de autorización en el componente DBViewer de Countly Server que permite a atacantes eludir controles de acceso mediante manipulación de JSON en el endpoint /o/db. El fallo reside en la detección deficiente de sub-pipelines en el sanitizador de etapas de agregación. Empresas en LATAM que usan Countly para analytics están expuestas a acceso no autorizado a bases de datos sensibles (CVSS 7.1).
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87998] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 un…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge base but then removed its administrator-owned external connection without a separate administrator check or a check for other dependent knowledge bases. A non-adminis…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86750] Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before …
Snipe-IT versions
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86754] Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allo…
Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authorization codes for bearer tokens inheriting full admin API permissions lasting up to 40 years.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87075] Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87644] Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a rem…
Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87570] Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote at…
Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severity: Medium)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87509] Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a l…
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87481] Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a r…
Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)