Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 43 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 43 min
[CVE-2026-57458] Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token…
Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at `POST /api/v1/oauth/token` for a normal bearer JSON Web Token (JWT) and refresh token. The resulting credentials are not restricted by the original API t…
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-93548] The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitle…
The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-84245] IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper co…
IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-50054] An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with acc…
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-93017] The `insights-operator-gather` ClusterRole grants the operator's service account read access to secr…
The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 ``` - apiGroups: …
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-76266] In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who c…
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-system commands with root privileges. The vulnerability is possible because the Linux package maintainer script trusts existing Splunk Enterprise installat…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-46434] wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the …
wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateView` grants access to anyone holding any one of `gym.manage_gym`, `gym.manage_gyms`, or `gym.gym_trainer` (OR logic via `WgerMultiplePermissionRequired…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-87782] The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change role…
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106492] Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @back…
Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. T…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-58841] In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due …
In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105634] Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_up…
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrat…
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad de escalada de privilegios en LaraDashboard anterior a 1.4.8
LaraDashboard versiones anteriores a 1.4.8 contiene una falla en la gestión de privilegios que permite a usuarios autenticados con permisos de edición de roles escalar a Superadmin, renombrando roles o asignándose permisos de suplantación de cuenta (user.login_as). Esto habilita acceso a funciones altas de actualización e instalación de módulos, exponiendo servidores en producción a ejecución remota de código en entornos empresariales de México y Latinoamérica.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-97644] The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr…
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — includi…