Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad de escalación de privilegios en Mattermost permite acceso no autorizado a canales restringidos
Mattermost versiones 11.9.0, 11.8.4, 11.7.7 y 10.11.22 o anteriores presentan una falla en la validación de permisos de gestión de miembros de canal durante la creación de ejecuciones de playbooks. Un miembro autenticado del canal puede adicionar usuarios arbitrarios a canales restringidos mediante el campo propietario de la ejecución. Esta vulnerabilidad (MMSA-2026-00677, CVSS 7.1) afecta principalmente a organizaciones en LATAM que utilizan Mattermost como plataforma de colaboración interna con canales de acceso controlado.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad alta en CAPEv2: falta de validación de propiedad en API REST
CAPEv2 hasta el commit 471ee4b presenta una falla de control de acceso en sus endpoints REST que permite a usuarios autenticados leer y eliminar análisis de malware enviados por otros usuarios. Los atacantes pueden enumerar todas las tareas del sistema y borrar análisis arbitrarios sin verificación de propiedad, comprometiendo la integridad de investigaciones de seguridad en laboratorios de análisis dinámico.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90537] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid dail…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62089] Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse…
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-38056] A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmwar…
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured l…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81211] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-89054] A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authen…
A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for event configuration and SNMP data collection (which enable and disable event definitions and data-collection sources) are re…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88959] Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoi…
Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or user roles can POST directly to admin/users/add or admin/users/edit endpoints to create new administrator accounts or change the existing administrator's password, ga…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-4129] There is an improper access control vulnerability in NI SystemLink that may allow an authenticated u…
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84821] Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Unauthenticated Broken Access Control in WP Fast Total Search
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81799] Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 version…
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81801] Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Subscriber Settings Change in WP-Stateless
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81794] Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81786] Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions…
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite escalada de privilegios
La cámara IP GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a usuarios invitados sobrescribir la configuración del dispositivo y reemplazar la contraseña del administrador a través del servicio SSVR. Esta falla afecta directamente a sistemas de videovigilancia desplegados en México y Latinoamérica, poniendo en riesgo el acceso no autorizado a infraestructura alta de seguridad física.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-14873] The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeo…
The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79324] Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/mo…
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86762] Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware gro…
Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a result, although a deactivated account is correctly refused at web login, its existing API token continues to authenticate and to grant read and write access to the REST API (assets, …
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86759] Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any a…
Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87036] Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.