Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-85058] Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a clie…
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths. When anonymous access is enabled and topic ACLs restrict writes, a remote client can set an ACL-protected topic as the Last Will Topic during CONNECT and perform…
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad de elusión de autorización en Master Addons for Elementor hasta v3.2.2
El plugin Master Addons for Elementor para WordPress es vulnerable a elusión de autorización en todas las versiones hasta la 3.2.2, permitiendo que atacantes autenticados con rol de colaborador ejecuten acciones no autorizadas. Esta vulnerabilidad afecta especialmente a agencias web, diseñadores freelance y empresas en LATAM que utilizan Elementor para gestionar sitios corporativos. Con CVSS 8.1, representa un riesgo alto para la integridad y confidencialidad del contenido.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89413] The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to,…
The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete any arbitrary Filter Gallery records — including all associated filters, image…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54671] WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an…
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional access for every authenticated user. The methods in web/controle/InternoControle.php, including listarUm, alterar, and excluir, accept user-controlled id or…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54519] AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and o…
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying through the related Agent that the record belongs to req.user. An authenticated attacke…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61596] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render entry points: (a) the initial HTTP GET render, (b) SPA `url_change` navigation, and (c) `{% live_ren…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61592] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92794] OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one…
OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download tokens without authentication.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92783] Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, a…
Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92780] KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowi…
KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator accounts or grant themselves administrative privileges without proper authorization.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92763] Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters…
Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security-relevant settings like node executors and SSH key paths that affect job execution.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92772] Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endp…
Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary properties including identifier, version, and license key to deploy malicious plugins.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92753] PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts…
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92761] WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only …
WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH keys, and manage ISO images by exploiting the get_instance gate that only checks grant existence.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92762] Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled f…
Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, docker images, and variables to execute arbitrary commands in the container.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92729] SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytic…
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61595] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-17526] Keycloak is an open-source identity and access management solution. A vulnerability was discovered w…
Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative control over the realm, including the ability to manage users, clients, and roles.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-82964] Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows …
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it copies the original security descriptor, but the driver opened the virtualization target object with GENERIC_WRITE and FILE_WRITE_ATTRIBUTES…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-74909] Keycloak provides a policy enforcer to protect applications by matching incoming web requests agains…
Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded characters, such as those representing semicolons or directory traversal segments. An authenticated user can use these encoded characters to trick the enforcer int…