Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81996] Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privileg…
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78626] The Okta Access Gateway improperly handles input sanitization and regular expression evaluation with…
The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75990] Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary c…
Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77774] Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Securi…
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-76202] Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privileg…
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77108] Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privileg…
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77109] Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privileg…
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77111] Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Securi…
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70283] Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locall…
Incorrect authorization in Windows Win32K allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82053] A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections ca…
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control con…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86665] A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the functio…
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-33388] An access control vulnerability was discovered in the Credentials Manager functionality due to insuf…
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who d…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86544] knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code acti…
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86437] Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with o…
Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which exec…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86498] In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed…
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/09/2026
[CVE-2026-76560] A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an …
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a dir…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19283] IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator coul…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85619] AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in autho…
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85620] Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validatio…
Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85512] A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vu…
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.