Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1805
Esta semana
RSS
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad alta en ManageEngine Password Manager Pro y PAM360 permite eludir autenticación
ManageEngine Password Manager Pro (versiones anteriores a 13232) y PAM360 (versiones anteriores a 8551) presentan una vulnerabilidad de elusión de autenticación (CVSS 8.8) por validación incorrecta de SAML. Esto permite a atacantes acceder a gestores de credenciales sin autenticación válida, comprometiendo todas las contraseñas almacenadas en la solución. Afecta principalmente a empresas medianas y grandes en México y LATAM que utilizan estas herramientas para administración centralizada de accesos.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59501] CWE-284: Improper Access Control
CWE-284: Improper Access Control
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59505] CWE-284: Improper Access Control
CWE-284: Improper Access Control
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59499] CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19484] @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthent…
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a boundary of exactly 252 bytes makes the search needle 256 bytes, which truncates …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19481] @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who ca…
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-11840] Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions be…
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18146] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo…
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in the…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18945] The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its…
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-49473] @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Ce…
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain circumstances, the middleware matches incoming requests against Cedar action map…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-47717] FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3…
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-71473] A flaw was found in the `search-v2-operator` component. A user with specific administrative permissi…
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the replacement of container images. This ultimately results in container image injection on the managed cluster, potentially com…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73493] Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.2…
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated fragmented message and drive unbounded heap growth in the server JVM, resulting in denia…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73495] blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0…
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names and values, including X-Forwarded-For and internal authorization headers, that a …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73498] MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload_attachment_direct() without calling validate_safe_path. An authenticated MCP client can read any file accessible to the…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19003] A data source definition containing an over-length file path setting may cause the MongoDB BI Connec…
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or fol…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-71469] A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests …
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).
M Alto vulnerabilidad
12/08/2026
[CVE-2026-10534] IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF…
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17485] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain s…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.