Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Alto vulnerabilidad
03/08/2026
[CVE-2026-68586] SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionD…
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including an anonymous reader when publish Basic Auth is …
M Alto vulnerabilidad
03/08/2026
[CVE-2026-68587] SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDelet…
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rendered block DOM without publish-access checks. Anonymous readers or publish RoleReader tokens can supply a heading block ID to read full rendered content of publish-disabled documents that should be re…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-20483] In Telephony, there is a possible escalation of privilege due to a missing permission check. This co…
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14930] The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or owners…
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-67527] OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/wo…
OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve Storages::FileLink records by raw id, detach or hard-delete existing FileLinks, and re-parent FileLinks from other projects to an attacker-controlled work packa…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15397] The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all…
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install a…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12500] The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX a…
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-14356] The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, a…
The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrat…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-50622] Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache …
Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-54719] goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, th…
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs and block lists. This issue is fixed in version 2.1.1. This vulnerability exists due to an incomple…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-16184] IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication…
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-49258] Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and belo…
Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration …
M Alto vulnerabilidad
28/07/2026
[CVE-2026-15025] The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPre…
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and automator_mautic_render_contact_fields AJAX actions due to a missing capability check and missing nonce v…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14168] A low privileged remote attacker can gain administrator privileges due to missing authorization at t…
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14924] The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability,…
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66473] Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment
J Alto vulnerabilidad
27/07/2026
[CVE-2026-65922] An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with li…
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59535] Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Unauthenticated Broken Access Control in Thrive Product Manager
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59536] Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Unauthenticated Broken Access Control in CoCart – Headless ecommerce
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59529] Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store