Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
21/08/2026
[CVE-2026-30866] Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can ac…
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-49217] Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorizati…
Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enabled. Upgrade to Mailu 2024.06.52 to receive a patch or, as a workaround, turn the REST API off.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-14952] An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the …
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76355] In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the informat…
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer (REST) API endpoint when Edge Processor is turned on. The vulnerability does not affect versions prior to 10.4. The vulnerability exists because the Edge Processor service endpoint lacks authentication …
M Alto vulnerabilidad
19/08/2026
[CVE-2026-19875] IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email…
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-56677] 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint i…
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js without restricting private or loopback destinations, allowing unauthenticated attackers when dashboard login is disabled to scan internal services and reflect OIDC di…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75479] JimuReport contains an authentication bypass vulnerability in the report folder template listing end…
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75060] In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP too…
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19908] PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows networ…
PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XCB daemon. The issue results from the lack of authentication prior to a…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-73673] Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability tha…
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentica…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73666] OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo …
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This i…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-65941] In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network a…
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad alta de autenticación faltante en sistema POS de FitSoft (CVE-2026-19426)
El sistema POS desarrollado por FitSoft contiene una vulnerabilidad de autenticación ausente que permite a atacantes remotos no autenticados acceder y operar directamente el sistema. Este defecto afecta principalmente a comercios minoristas, restaurantes y negocios de fitness en LATAM que utilizan esta solución. Con puntuación CVSS 8.2, representa un riesgo alta para la integridad de transacciones y datos de clientes.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73246] Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/s…
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands, environment variables, HTTP headers, connection details, plaintext credentials, and execution identifiers while the main API o…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66875] In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attac…
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73222] Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the…
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute endpoint passes the prompt request-body field to executeLocalTask(), and POST /api/i…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-64921] Missing authentication for critical function in Microsoft Office SharePoint allows an authorized att…
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62777] Missing authentication for critical function in Windows License Manager allows an authorized attacke…
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61367] Missing authentication for critical function in Windows Remote Desktop Services allows an authorized…
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61364] Missing authentication for critical function in Windows Remote Desktop Services allows an authorized…
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.