Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1751
Esta semana
RSS
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74872] openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirl…
openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74875] openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema libra…
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74799] SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps w…
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74800] SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin…
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
? Crítico alerta
17/08/2026
CISA Adds One Known Exploited Vulnerability to Catalog 
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog . CVEs relacionados: CVE-2025-62593.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-19977] A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function http…
A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Validation. Performing a manipulation results in improper authentication. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19961] A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of…
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19959] A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetu…
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclos…
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-74790] Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change…
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73056] SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication atte…
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an …
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73061] Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al…
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de inyección de objetos PHP en plugin ARForms para WordPress
El plugin ARForms (Contact Form, Survey, Quiz & Popup Form Builder) para WordPress contiene una vulnerabilidad de inyección de objetos PHP (CVE-2024-13784, CVSS 9.8) en versiones hasta 1.8.5 que permite a atacantes no autenticados inyectar objetos maliciosos mediante deserialización de datos en envíos de formularios. Aunque actualmente no hay cadenas POP conocidas explotadas, esta vulnerabilidad expone sitios web en México y Latinoamérica que utilicen este plugin, afectando formularios de contacto, encuestas y popups que interactúan directamente con usuarios.
M Crítico vulnerabilidad
16/08/2026
Plugin Solace Extra para WordPress vulnerable a modificación no autorizada de datos (CVE-2026-18316)
El plugin Solace Extra en versiones hasta 1.6.0 permite a atacantes no autenticados modificar o eliminar datos a través de la función import_zip() que carece de validación de permisos. La vulnerabilidad afecta sitios WordPress en México y LATAM que usan este plugin, exponiendo contenido, configuraciones y bases de datos. La verificación de nonce insuficiente permite bypass de controles de seguridad estándar de WordPress.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Frontend Admin para WordPress (CVE-2026-18432)
El plugin Frontend Admin by DynamiApps para WordPress contiene una falla de escalada de privilegios en versiones hasta 3.29.9 que permite a usuarios no autenticados obtener permisos de administrador. La vulnerabilidad reside en la función ActionUser::conditions_logic() que omite validaciones de autorización cuando recibe parámetros no numéricos, afectando directamente a sitios WordPress en México y LATAM que usan este plugin. Con puntuación CVSS 9.8, representa riesgo crítico para tiendas de comercio electrónico, portales corporativos y sistemas de contenido.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin ProSolution WP Client para WordPress
El plugin ProSolution WP Client para WordPress (versiones hasta 2.0.10) permite a atacantes cargar archivos arbitrarios explotando validación insuficiente en la función proSol_handleFileUpload. La vulnerabilidad reside en la falta de validación del encabezado Content-Disposition, que puede sobrescribir nombres de archivo permitidos. Con CVSS 9.8, afecta directamente a sitios empresariales, e-commerce y portales de clientes en LATAM que utilicen este plugin.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica en plugin ProSolution WP Client permite eliminación arbitraria de archivos
El plugin ProSolution WP Client para WordPress (versiones ≤2.0.8) contiene una falla de validación de rutas que permite a atacantes no autenticados eliminar archivos arbitrarios del servidor. Esta vulnerabilidad puede ser explotada para ejecutar código remoto eliminando archivos críticos de WordPress, comprometiendo completamente el sitio web. Afecta directamente a pequeñas y medianas empresas en LATAM que utilizan este plugin en plataformas de comercio electrónico y gestión de contenidos.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19924] A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability…
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73052] SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d…
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73053] SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func…
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73043] SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat…
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the …