Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Crítico vulnerabilidad
Hace 4 días
Vulnerabilidad crítica de autorización en Totolik A3002MU 1.0.0-B20230403.1455
Se identificó una debilidad en el router Totolink A3002MU versión 1.0.0-B20230403.1455 que permite bypass de autenticación en la función sub_40FCFC del componente /bin/boa. Un atacante remoto puede manipular el mecanismo de verificación de autorización sin credenciales válidas. El exploit está disponible públicamente, exponiendo dispositivos conectados en redes corporativas y residenciales de LATAM a acceso no autorizado.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-16346] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Crítico vulnerabilidad
22/09/2026
CVE-2026-25254: Autorización deficiente permite Ejecución Remota de Código vía SocketIO
Una vulnerabilidad crítica (CVSS 9.8) en la interfaz SocketIO de múltiples productos permite a atacantes ejecutar código remoto explotando controles de autorización inadecuados. Este vector afecta principalmente servidores web y aplicaciones en tiempo real expuestas en LATAM. La exposición es inmediata si los sistemas están conectados a internet sin restricciones de acceso.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-85878] Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate pri…
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-70200] Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a…
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-76420] A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for …
A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption parameters for the AJP connector at boot time. An attacker could exploit this vulnerability by sending crafted packets to the…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-53952] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installatio…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-50152] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds …
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-16279] An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R…
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-53548] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password or field=sudoPassword query without enforcing host ownership during credential resolution. A failed requester-scoped loo…
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-55166] Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME …
Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud instance metadata or internal services from Lemur network context, potentially obtaining credentials available to the host. T…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73644] OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identi…
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different user. Both dn: and u: or bare authzid forms could therefore let an au…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-59118] Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges…
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-18367] A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos…
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-62835] Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over …
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56160] Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate pri…
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
S Crítico vulnerabilidad
21/07/2026
[CVE-2026-28312] SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s …
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
M Crítico vulnerabilidad
07/07/2026
[CVE-2026-34048] Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. …
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.
L Crítico vulnerabilidad
30/06/2026
[CVE-2026-7663] IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP p…
IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.
F Crítico vulnerabilidad
30/06/2026
[CVE-2026-6556] @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount path…
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the actual prefixed request path. Applications that use path-scoped middleware for authen…