Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-78023] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authoriz…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta de bypass de autorización en OctoCloud (CVE-2026-19083)
OctoCloud versiones 1.12.06 anteriores a 1.12.07 contiene una vulnerabilidad de bypass de autorización (CVSS 8.8) que permite a atacantes acceder a funcionalidades sin restricción adecuada de controles de acceso (ACLs). Esta vulnerabilidad afecta directamente a empresas manufactureras y comercializadoras de México y LATAM que utilizan OctoCloud para gestión de importaciones y exportaciones. El riesgo incluye acceso no autorizado a datos sensibles de operaciones comerciales internacionales.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107270] Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authen…
Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequential id in POST requests to /api/groups/, /api/templates/, /api/pages/ or /api/smtp/ to overwrite and reassign objects, locking out owners and exposing victims' re…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-93678] IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitiv…
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103009] Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information …
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102406] Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data…
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106100] Payload is a free and open source headless content management system. In @payloadcms/db-mongodb vers…
Payload is a free and open source headless content management system. In @payloadcms/db-mongodb versions before 3.87.0 and canary versions before 4.0.0-canary.20, an authenticated user who can update a document can modify fields that field-level write access control does not permit that user to change. The Postgres and SQLite adapters are not affected. This issue is fixed in versions 3.87.0 and 4.…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105761] Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<…
Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the requested application and tenant. An authenticated workspace member could therefore…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105629] Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy r…
Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. T…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105631] Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and …
Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that gra…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105633] Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpo…
Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the iss…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104971] Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a so…
Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104975] Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints i…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-b…
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad alta de escalada de privilegios en Ultimate Member 2.13.1 y anteriores
Se ha identificado una vulnerabilidad de omisión de autorización en el plugin Ultimate Member para WordPress que permite a atacantes escalar privilegios mediante claves controladas por el usuario. Esta falla afecta versiones hasta 2.13.1 y representa un riesgo alta (CVSS 8.8) para sitios web corporativos, plataformas de membresía y comunidades online en México y Latinoamérica que dependen de este plugin para gestionar roles y permisos de usuarios.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad de omisión de autorización en YesWiki anterior a 4.6.7 afecta integridad de contenido
YesWiki versiones anteriores a 4.6.7 contiene una falla de autorización en la API de comentarios (ruta editComment) que permite a usuarios autenticados con privilegios bajos sobrescribir páginas y comentarios arbitrarios mediante manipulación del parámetro pagetag. Un atacante puede enviar solicitudes POST al endpoint api/comments para eludir controles de acceso por página (ACLs) y reemplazar contenido, afectando la integridad de wikis corporativas y colaborativas en organizaciones de LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-100514] Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.
Unauthenticated Insecure Direct Object References (IDOR) in REST API Log
M Alto vulnerabilidad
01/10/2026
[CVE-2026-100517] Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 …
Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103252] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an aut…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled host…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103247] n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs b…
n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103246] n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inl…
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.