Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 min
Buscando: "Ni" — 890 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-62674] Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prio…
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a session can replace that shared agent bundle through omnigent/server/routes/session…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-77087] Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attack…
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-63343] Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image c…
Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance metadata API. The `exec-output` and `templates/` paths were patched in a prior release using `Lstat` rejection and `os.OpenRoot…
M Crítico vulnerabilidad
Hace 3 días
Vulnerabilidad crítica en SiYuan anterior a v3.7.4 permite traversal de directorios
SiYuan anterior a la versión 3.7.4 no valida correctamente el parámetro packageName en los endpoints de instalación y desinstalación de Bazaar, permitiendo que administradores autenticados ejecuten ataques de traversal de directorios. Un atacante con acceso administrativo puede escribir archivos arbitrarios en cualquier ubicación del sistema o eliminar directorios recursivamente mediante valores crafted en packageName, afectando potencialmente datos críticos en servidores y estaciones de trabajo en LATAM.
M Crítico vulnerabilidad
Hace 3 días
Inyección de comandos crítica en Comfast CF-N1-S 2.6.0.1 (CVE-2026-77683)
Se ha descubierto una vulnerabilidad crítica (CVSS 9.9) en el router Comfast CF-N1-S versión 2.6.0.1 que permite inyección de comandos remotos a través del parámetro timestr en la función /cgi-bin/mbox-config. Un atacante puede ejecutar comandos del sistema sin autenticación. El exploit está disponible públicamente, incrementando el riesgo de explotación inmediata en infraestructuras de pequeña y mediana empresa en LATAM que utilizan este equipo.
M Crítico vulnerabilidad
Hace 3 días
Vulnerabilidad crítica de autenticación en plugins de WordPress para WooCommerce (CVE-2026-77264)
El plugin 'Automation Web Platform – Notifications and OTP for WooCommerce' y el complemento 'Advanced Country Code' para WordPress presentan un bypass de autenticación en versiones hasta 4.8.6. La función handle_email_otp_return() expone el token de login secreto en respuestas públicas de solicitudes OTP, permitiendo acceso no autorizado sin validación de correo. Afecta directamente a tiendas en línea, plataformas de e-commerce y sitios con autenticación de dos factores basada en OTP en México y Latinoamérica.
M Crítico vulnerabilidad
Hace 3 días
Ejecución remota de código en SPIP anterior a 4.4.20 (CVE-2026-77647)
SPIP versiones anteriores a 4.4.20 contiene una vulnerabilidad crítica (CVSS 9.8) que permite a atacantes no autenticados ejecutar código arbitrario de forma remota, explotada activamente desde agosto de 2026. La falla radica en la identificación incorrecta de bloques PHP y el manejo deficiente de caracteres especiales por var_export. Afecta directamente a instituciones, medios digitales y PyMEs que usan SPIP como gestor de contenidos en la región.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-77148] A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the fi…
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73257] Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica…
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use …
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-77022] A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the functi…
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks…
M Crítico vulnerabilidad
Hace 4 días
Carga arbitraria de archivos en IT Residence <= 3.2.1 (CVE-2026-74014)
Vulnerabilidad crítica (CVSS 9.9) en IT Residence versiones 3.2.1 y anteriores permite a suscriptores cargar archivos arbitrarios en servidores afectados. Esta falla expone sistemas de gestión inmobiliaria, comunes en empresas de administración de propiedades y desarrolladores en México y Latinoamérica, a ejecución remota de código y compromiso total de infraestructura.
M Crítico vulnerabilidad
Hace 4 días
Carga arbitraria de archivos en Smart Cleaning ≤ 4.8.6 afecta suscriptores
Se reporta una vulnerabilidad crítica (CVSS 9.9) en Smart Cleaning versiones 4.8.6 y anteriores que permite a usuarios suscritos cargar archivos arbitrarios en servidores. Esta falla compromete la integridad de sistemas y facilita inyección de malware en infraestructuras empresariales de LATAM. Afecta especialmente a empresas que utilizan esta plataforma para gestión de servicios de limpieza en múltiples sedes.
M Crítico vulnerabilidad
Hace 4 días
Escalada de Privilegios sin Autenticación en Abandoned Cart Pro para WooCommerce ≤ 10.4.0
Se identificó una vulnerabilidad crítica (CVSS 9.8) de escalada de privilegios sin autenticación en el plugin Abandoned Cart Pro para WooCommerce en versiones 10.4.0 y anteriores. Esta falla permite a atacantes remotos obtener acceso administrativo en tiendas WooCommerce sin credenciales válidas. Afecta especialmente a pequeñas y medianas empresas en LATAM que operan plataformas de e-commerce sin parchear regularmente sus plugins.
M Crítico vulnerabilidad
Hace 4 días
Ejecución remota de código crítica en Query Wrangler hasta versión 1.5.57 (CVE-2026-73992)
Se ha identificado una vulnerabilidad crítica de ejecución remota de código (RCE) en Query Wrangler versiones 1.5.57 e inferiores, con puntuación CVSS de 9.9. Los atacantes pueden ejecutar código arbitrario en sistemas que usen versiones vulnerables, comprometiendo bases de datos y aplicaciones dependientes. Esta vulnerabilidad afecta directamente a infraestructuras de procesamiento de consultas en empresas de telecomunicaciones, finanzas y servicios en la región.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-13097] A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri…
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-75860] The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica…
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-76589] A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 …
A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-76590] A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some …
A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-76310] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who …
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk r…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-76584] A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some…
A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.