Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 1489 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Crítico vulnerabilidad
07/09/2026
Vulnerabilidad crítica en controladores Advantech WISE-6610 afecta sistemas industriales
Se identificó una vulnerabilidad crítica (CVSS 9.9) en múltiples modelos de controladores Advantech WISE-6610 (versión 1.2.1_20251110) que afecta la librería Node-RED. La vulnerabilidad permite manipulación de argumentos en la función nodered_lib_apply, comprometiendo sistemas de automación industrial en plantas, manufactura y infraestructura crítica en LATAM. Afecta aplicaciones desplegadas en entornos operacionales que dependen de estos dispositivos para monitoreo y control remoto.
M Crítico vulnerabilidad
07/09/2026
Vulnerabilidad crítica en controladores Advantech WISE-6610 permite manipulación de certificados
Se identificó una vulnerabilidad crítica (CVSS 9.9) en múltiples modelos de controladores industriales Advantech WISE-6610 (versión 1.2.1_20251110) que afecta el manejador de eliminación de certificados de estación base. Esta vulnerabilidad permite a atacantes manipular funciones críticas de autenticación en sistemas de control industrial, poniendo en riesgo infraestructuras críticas, plantas de manufactura y sistemas de energía en operación en México y Latinoamérica.
M Crítico vulnerabilidad
06/09/2026
Inyección de comandos OS crítica en Tenda HG10 (CVE-2026-86167)
Se identificó una vulnerabilidad crítica (CVSS 9.9) en el router Tenda HG10 modelo 300001138 que permite inyección de comandos del sistema operativo a través del parámetro fmgpon_loid en la función formgponConf. La vulnerabilidad es explotable remotamente y cuenta con exploits públicos disponibles. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos equipos en infraestructuras de acceso a internet.
M Crítico vulnerabilidad
06/09/2026
CVE-2026-86165: Vulnerabilidad crítica de desbordamiento de búfer en Tenda HG10 300001138
Se identificó una vulnerabilidad de desbordamiento de búfer (buffer overflow) en el router Tenda HG10 modelo 300001138, específicamente en la función formURL del archivo /boaform/admin/formURL. Un atacante remoto puede manipular los parámetros Keywd/urlFQDN para ejecutar código arbitrario sin autenticación previa. El exploit es público y activamente explotado en la región LATAM, afectando principalmente a PyMEs con infraestructura de redes domésticas y pequeñas oficinas.
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-16310] The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over t…
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-86152] A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::T…
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-86153] A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::Set…
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-86151] A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77…
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-86148] A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the functio…
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-86149] A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing …
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-86190] WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns …
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal d…
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de autenticación en Lara Dashboard anterior a v1.3.0
Lara Dashboard versiones anteriores a 1.3.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en la ruta screenshot-login que permite a atacantes no autenticados acceder como cualquier usuario registrado mediante su correo electrónico cuando APP_ENV no está configurado en producción. Explotando el endpoint GET /screenshot-login/{email}, los atacantes obtienen sesiones completamente autenticadas con acceso a administración de usuarios, configuraciones y datos sensibles. Esta falla afecta principalmente a instancias de desarrollo y staging expuestas en entornos LATAM.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica en Cua computer-server permite ejecución remota de comandos sin autenticación
Cua computer-server versiones anteriores a 0.3.42 omiten validación de autenticación cuando la variable de entorno CONTAINER_NAME no está configurada, exponiendo el puerto TCP 8000 a ataques no autenticados. Los atacantes pueden ejecutar comandos arbitrarios, acceder a sistemas de archivos y obtener shells interactivas en servidores empresariales en México y LATAM que utilicen esta versión vulnerable.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de ejecución remota sin autenticación en AutoAgent (CVE-2026-86124)
AutoAgent contiene una vulnerabilidad de ejecución remota de código sin autenticación en su servidor TCP que se vincula a todas las interfaces de red, permitiendo a atacantes ejecutar comandos bash arbitrarios como root. Los atacantes pueden conectarse al puerto expuesto y acceder a directorios del host montados en contenedores, comprometiendo completamente la confidencialidad, integridad y disponibilidad de la infraestructura. Esta vulnerabilidad afecta servidores en entornos containerizados comunes en empresas de LATAM.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica en plugin ComboBlocks para WordPress permite inyección de hooks sin autenticación
El plugin 'The Post Grid and Gutenberg Blocks – ComboBlocks' en versiones 2.2.32 a 2.3.1 es vulnerable a inyección de hooks no autenticada, permitiendo a atacantes ejecutar acciones maliciosas en WordPress sin credenciales. La vulnerabilidad afecta miles de sitios web en México y LATAM que utilizan este plugin para construcción de contenido con Gutenberg, exponiendo datos y funcionalidades críticas del sitio.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-83627] The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulner…
The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leadi…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-81939] A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and arc…
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-78327] An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-78328] A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manage…
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-31020] In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to d…
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulner…