Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105697] Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.…
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/serv…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105740] Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any a…
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediate…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105691] Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places a…
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's pri…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-97283] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager adva…
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105638] Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and an incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address. The verifier extends django.views.View rather than DRF's APIView, so the con…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105639] Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logge…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer u…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105640] Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses return…
Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to th…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105641] Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and …
Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community de…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105636] Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/a…
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. …
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-105637] Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in ap…
Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, dr…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-103352] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-88395] GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords p…
GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-79820] A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
M Crítico vulnerabilidad
Hace 4 días
Vulnerabilidad crítica de desbordamiento de búfer en Totolik A3002MU 1.0.0-B20230403.1455
Se ha identificado una vulnerabilidad de desbordamiento de búfer basado en pila (CVSS 10.0) en el manejador de reglas QoS del router Totolik A3002MU. La vulnerabilidad afecta el componente /boafrm/formIpQoS y puede ser explotada remotamente manipulando parámetros como addQos/comment/entry_name. El exploit ha sido divulgado públicamente, elevando el riesgo para infraestructuras críticas que utilizan este dispositivo en México y Latinoamérica.
M Crítico vulnerabilidad
Hace 4 días
Vulnerabilidad crítica de autorización en Totolik A3002MU 1.0.0-B20230403.1455
Se identificó una debilidad en el router Totolink A3002MU versión 1.0.0-B20230403.1455 que permite bypass de autenticación en la función sub_40FCFC del componente /bin/boa. Un atacante remoto puede manipular el mecanismo de verificación de autorización sin credenciales válidas. El exploit está disponible públicamente, exponiendo dispositivos conectados en redes corporativas y residenciales de LATAM a acceso no autorizado.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-105209] ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: wh…
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and r…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-105215] ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1…
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-105207] ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and externa…
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account…
M Crítico vulnerabilidad
Hace 5 días
Inyección SQL ciega crítica en Unlimited Elements for Elementor (CVSS 9.3)
Vulnerabilidad de inyección SQL en el plugin Unlimited Elements for Elementor (versiones hasta 2.0.20) permite a atacantes ejecutar consultas maliciosas contra bases de datos de sitios WordPress. Afecta principalmente a agencias digitales y empresas en LATAM que utilizan este plugin de diseño para construir landing pages y portales. El impacto es crítico: acceso no autorizado a datos sensibles, robo de credenciales y compromiso total del sitio.
M Crítico vulnerabilidad
Hace 5 días
Vulnerabilidad crítica de inyección de comandos OS en Ahsay AhsayCBS hasta v10.3.2
Se ha identificado una falla crítica (CVSS 10.0) en Ahsay AhsayCBS versiones hasta 10.3.2 que permite inyección de comandos del sistema operativo a través de manipulación del parámetro 'random' en el endpoint /rps/api/json/UpdateReceivers.do del componente Replication Receiver. El ataque es ejecutable remotamente sin autenticación y el exploit está públicamente disponible, afectando directamente a soluciones de backup y recuperación de desastres ampliamente utilizadas en empresas LATAM.