Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 min
Buscando: "Ui" — 669 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-19274] IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator coul…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlle…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-82923] The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or n…
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads di…
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Submariner: inyección de configuración en modo cert-auth
Se identificó una falla en Submariner que permite inyección de configuración arbitraria en modo autenticación por certificados. Un cluster malicioso puede explotar esta vulnerabilidad publicando un CableName con saltos de línea y directivas de ipsec.conf sin validación previa, comprometiendo la seguridad de redes híbridas y multi-cluster. El impacto afecta directamente a empresas en LATAM con infraestructuras Kubernetes distribuidas en cloud público y privado.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Joro framework: exposición de API local sin autenticación
Joro, un framework de pruebas web, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.1 que expone una API local sin autenticación en 127.0.0.1:9090 con política CORS permisiva. Un atacante puede ejecutar JavaScript malicioso desde cualquier sitio visitado para cargar plugins nativos y comprometer completamente el sistema. Esta exposición afecta principalmente a equipos de seguridad y desarrolladores que utilizan Joro para análisis de aplicaciones web en infraestructuras empresariales de LATAM.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-53611] Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary…
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in the input…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84699] Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local ac…
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75604] Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and…
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-79748] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP server configurations and then immediately spawn the configured stdio process via child_process.spawn. Authentication is requi…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82693] A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function …
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82694] A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSe…
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
31/08/2026
ToolJet anterior a v3.16.208: vulnerabilidad crítica de escalamiento de privilegios entre organizaciones
ToolJet antes de la versión 3.16.208 no valida correctamente la pertenencia de usuarios autenticados a la organización especificada, permitiendo a usuarios Builder leer, modificar y eliminar tablas entre diferentes tenants. Los atacantes pueden extraer identificadores de organización de endpoints públicos y explotar operaciones de esquema para acceder a datos sensibles de otras empresas, representando riesgo crítico para empresas LATAM que utilizan esta plataforma en producción.
M Crítico vulnerabilidad
31/08/2026
Vulnerabilidad crítica en ToolJet anterior a v3.16.208 permite acceso no autorizado entre organizaciones
ToolJet antes de la versión 3.16.208 presenta una falla crítica (CVSS 9.6) en la validación de propiedad de organizationId en rutas de escritura y eliminación de base de datos. Usuarios con rol de constructor pueden crear, modificar o eliminar tablas en bases de datos de otras organizaciones en instancias compartidas, comprometiendo la integridad de datos entre inquilinos. En entornos empresariales de LATAM con múltiples clientes en una sola instancia, esto representa riesgo de pérdida permanente de información y manipulación de esquemas.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82860] @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence…
@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.
M Crítico vulnerabilidad
29/08/2026
Vulnerabilidad crítica en argocd-mcp 0.8.0: exposición de interfaz HTTP sin autenticación
ArgoCD MCP versión 0.8.0 expone su transporte HTTP en todas las interfaces de red sin requerir credenciales cuando ARGOCD_API_TOKEN está configurado. Atacantes con acceso a la red pueden invocar la superficie completa de herramientas utilizando el token del operador para crear aplicaciones, ejecutar sincronizaciones y modificar recursos de Argo CD. Esta vulnerabilidad afecta crítica a infraestructuras de CI/CD en empresas que operan Kubernetes en LATAM.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-77012] The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its…
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied conten…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16947] The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a …
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success respon…
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-19295] IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operatin…
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing …
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-18527] IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow…
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82266] Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t…
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.