Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-89301] The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file…
The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on a…
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-107813] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster r…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, chang…
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-107811] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenti…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth…
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-105883] Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incor…
Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1.
M Alto vulnerabilidad Nuevo
Hace 18 horas
Vulnerabilidad alta de autorización en TMS Amelia ameliabooking permite eludir controles de acceso
Una vulnerabilidad de autorización faltante (CVE-2026-96461, CVSS 7.5) en TMS Amelia ameliabooking versiones hasta 2.4.10 permite a atacantes eludir controles de acceso mediante configuración incorrecta de niveles de seguridad. Esta falla afecta principalmente a plataformas de reservas y gestión de citas en sectores turismo, salud y servicios en LATAM, exponiendo datos sensibles de clientes y operaciones altas.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-83947] Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a n…
Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta de autorización en hMailServer 6.0.0-6.3.5 permite escalada de privilegios local
hMailServer (versiones 6.0.0 a 6.3.5 en Windows) presenta falta de validación de permisos en objetos COM, permitiendo a usuarios locales sin credenciales del servidor leer/escribir archivos arbitrarios con privilegios de cuenta de servicio y suplantar remitentes. Esta vulnerabilidad afecta principalmente servidores de correo empresariales en LATAM que usan versiones antiguas sin hardening de DCOM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-71895] An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to re…
An authorization vulnerability in Apache DolphinScheduler allows authenticated non-admin users to retrieve Kubernetes configuration data intended for administrator-managed cluster configuration. The exposed kubeconfig data contains credentials that may allow users to authenticate directly to the Kubernetes API outside DolphinScheduler. The impact depends on the permissions granted to the disclo…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107352] Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed a…
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No custo…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-96335] Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured …
Missing Authorization vulnerability in WPMU DEV Forminator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Forminator: from n/a through 1.57.2.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-82211] The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to se…
The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106387] Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote a…
Missing authorization in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106225] Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker …
Missing authorization in Autofill in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106191] Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who…
Missing authorization in Actor in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106194] Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote att…
Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106040] Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allow…
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk replica via EvictDiskReplica and BatchEvictDiskReplica. Attackers reaching the coro_rpc master port can evict DISK replicas across all tenants, deleting objects whose only remaining replica is on disk.
M Alto vulnerabilidad
Hace 3 días
Control de Acceso Roto sin Autenticación en BEAR hasta versión 1.2.2 (CVSS 7.3)
Se identificó una vulnerabilidad de control de acceso roto que permite a atacantes sin autenticación acceder a recursos protegidos en BEAR versiones 1.2.2 y anteriores. Esta falla afecta principalmente a servidores web y aplicaciones en México y LATAM que utilizan este software. El riesgo es elevado en entornos expuestos a internet sin validación adicional de permisos.
M Alto vulnerabilidad
Hace 3 días
Control de Acceso Roto en Progress Planner <= 1.10.0 (CVSS 8.8)
Progress Planner versiones 1.10.0 y anteriores contienen una vulnerabilidad de control de acceso roto que permite a suscriptores no autorizados acceder a recursos restringidos. Esta falla afecta principalmente a organizaciones en LATAM que utilizan esta herramienta para gestión de proyectos en entornos empresariales altas, exponiendo datos sensibles de planificación y operaciones.
M Alto vulnerabilidad
Hace 3 días
Control de Acceso Roto sin Autenticación en The7 versiones ≤ 14.2.2
Vulnerabilidad alta en el tema WordPress The7 permite a atacantes no autenticados acceder a funcionalidades restringidas y modificar configuraciones del sitio. Afecta principalmente a agencias digitales, e-commerce y portales corporativos en LATAM que utilizan esta plantilla popular. Con CVSS 7.5, el riesgo de compromiso de datos y defacement es alto.
M Alto vulnerabilidad
Hace 3 días
Control de acceso roto sin autenticación en Easy Digital Downloads versiones ≤ 3.7.1
Easy Digital Downloads, plugin de WordPress ampliamente usado en LATAM para venta de contenido digital, presenta una vulnerabilidad alta de control de acceso que permite a atacantes no autenticados acceder a funcionalidades restringidas. Esta falla afecta principalmente a tiendas digitales y plataformas de distribución de contenido en México y Latinoamérica que dependen de este plugin para gestionar transacciones y datos sensibles.