Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 min
Buscando: "Ni" — 1486 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en router D-Link DIR-878 120B05 permite desbordamiento de pila remoto
Se detectó una vulnerabilidad crítica (CVSS 9.9) en el router D-Link DIR-878 versión 120B05 que afecta la función SetDynamicDNSIPv6Settings. Un atacante remoto puede explotar esta falla manipulando los parámetros IPv6Address/Hostname para provocar un desbordamiento de pila (stack-based buffer overflow), potencialmente logrando ejecución remota de código. Este router es ampliamente utilizado en pequeñas y medianas empresas (PyMES) en México y LATAM para conectividad WAN.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90680] A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is th…
A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90608] A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function fo…
A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90607] A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNew…
A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90605] A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the…
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-90606] A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects…
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Crítico vulnerabilidad
13/09/2026
[CVE-2026-81648] The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check…
The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica de ejecución remota de código en The Events Calendar para WordPress hasta versión 6.17.4
The Events Calendar plugin para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones hasta 6.17.4. La falla reside en la función is_safe_widget_instance que puede ser eludida mediante métodos mágicos de PHP durante el pre-parseo, permitiendo a atacantes no autenticados ejecutar código arbitrario. Empresas en LATAM que operan sitios WordPress con este plugin están expuestas a compromisos críticos de integridad y disponibilidad.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-82845] The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metad…
The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the s…
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-75800] The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML…
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-53952] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installatio…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-72709] SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpo…
SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via autoriser(). Attackers can obtain a valid nonce, compute it for any action as the anonymous user, and invoke the editer_au…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-89009] WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header wit…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-89010] WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string vi…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-71644] An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef12345678…
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-84390] A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.…
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14563] The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before i…
The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14559] The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password befo…
The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-8778] The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for …
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-82100] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a d…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.