Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-55642] dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c…
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no stored password exists, while crates/dbx-web/src/main.rs binds the service to 0.0.0.0 on port 4224 by default. An unauthen…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-18265] OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability al…
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access t…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-15706] Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry …
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-63722] ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthentic…
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP POST request to the terminal endpoint with a password parameter to bypass authentication, a non-empty csrf parameter to sk…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-72529] A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions…
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-20357] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20357 are related to missing authentication for critical function i…
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica en ArcadeDB: autenticación SASL no aplicada en protocolo MongoDB
ArcadeDB versiones anteriores a 26.8.1 no valida credenciales SASL en comandos de datos del plugin MongoDB wire-protocol. Atacantes no autenticados pueden ejecutar inserciones, búsquedas, actualizaciones, eliminaciones y creación de bases de datos conectando al puerto 27017 sin credenciales. Afecta infraestructuras que exponen este servicio en empresas de LATAM con bases de datos sensibles.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica de autenticación en ArcadeDB anteriores a 26.8.1 (CVE-2026-75854)
ArcadeDB versiones anteriores a 26.8.1 presentan una vulnerabilidad crítica (CVSS 9.8) en el plugin de protocolo Redis que permite a atacantes no autenticados leer, escribir y eliminar datos. Los atacantes pueden conectarse al puerto Redis y ejecutar comandos arbitrarios contra cualquier base de datos del servidor sin proporcionar credenciales. Esta vulnerabilidad afecta especialmente a empresas en LATAM que utilizan ArcadeDB en entornos de producción con acceso a redes inseguras o expuestas.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-71566] FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware…
FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the user that created fakefish, power them on and off, and mount arbitrary …
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-50027] mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes…
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote attacker can upload arbitrary content into the memory store (write), retrieve stored document content (…
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-73849] Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r…
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email values to cause file_put_contents('config.php', $config) t…
M Crítico vulnerabilidad
14/08/2026
Vulnerabilidad crítica en getgrav/grav-plugin-api: escalada de privilegios en desactivación de 2FA
El paquete Composer getgrav/grav-plugin-api versiones
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73842] OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and …
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73843] OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, i…
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods i…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72776] AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that al…
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-14525] IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Serve…
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49827] WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1…
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chai…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59506] CWE-306: Missing Authentication for Critical Function
CWE-306: Missing Authentication for Critical Function
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49819] UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentica…
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers > 0` count check — a conditio…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73296] Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t…
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_t…