Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-17482] IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary cod…
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73656] Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to…
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where workerDeployment.findFirst() selects a deployment by friendlyId without an environmentId predica…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-19747] A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14…
A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-14525] IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Serve…
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73653] Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Br…
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73644] OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identi…
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different user. Both dn: and u: or bare authzid forms could therefore let an au…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73649] Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, t…
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73567] sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and …
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which seeds an ARC4 stream from Math.random() and new Date().getTime() because window.crypto.getRandomValues is unavailable ev…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-67614] CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SS…
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service with…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73532] Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered p…
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploa…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73533] Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered …
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administ…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-53791] rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated …
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized a…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66691] Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Unauthenticated Broken Access Control in Nokri
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66472] Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated SQL Injection in Everest Backup
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66478] Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Unauthenticated SQL Injection in Church Admin

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66465] Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66453] Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Salon booking system
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66458] Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated SQL Injection in RealPress
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66436] Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66446] Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization