Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93642] An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z…
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93643] When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an …
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93647] An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. …
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-100075] In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ct…
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending()…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92609] Session fixation in HTTP management authentication allows remote attackers to gain unauthorized acce…
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Crítico vulnerabilidad
25/09/2026
CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Crítico vulnerabilidad
25/09/2026
Vulnerabilidad crítica en plugin Bookly para WordPress permite acceso no autorizado a datos de reservas
El plugin Bookly para WordPress (versiones hasta 28.2) contiene una vulnerabilidad de Referencia Directa a Objetos (IDOR) en acciones AJAX que permite a atacantes acceder y manipular datos de reservas, sesiones y órdenes sin autenticación. Afecta directamente a negocios de servicios en LATAM que usan este plugin para gestionar citas y pagos online, exponiendo información de clientes y transacciones.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-89055] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in a…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product …
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-14281] The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo…
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/` and the absence of a key allowlist in the `finish_registration_logic` function, which…
? Crítico alerta
25/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-87902.
? Crítico alerta
25/09/2026
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Two Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-65660, CVE-2026-67279.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92288] Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow u…
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method de…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-95699] Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users acce…
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93291] Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-m…
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-13249] An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web manageme…
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-61741] http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies…
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, a…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-61732] Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl res…
Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compatible endpoint. Most open-source and self-deplo…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-97413] In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer unde…
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len = off - usr_len without validating that usr_len off causing an integer underflow, resulting in data_len wrappin…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-79766] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator can store attacker-controlled domain and email values through PATCH /users/acme-ssl-settings and trigger their interpolation into a certbot shell command through POST /users/acme-ssl-request. In src/backend/database/routes/acme-…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93425] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoD…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metac…