Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1751
Esta semana
RSS
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-61967] Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Privilege Escalation in miniorange otp verification
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28185] Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
Unauthenticated Broken Authentication in Log in with Google
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28149] Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28001] Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in WP Directory Kit
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28008] Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions…
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client)
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28142] Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated SQL Injection in Web Directory Free
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28148] Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated Bypass Vulnerability in Headless Single Sign On

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-27544] Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49827] WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1…
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chai…
M Crítico vulnerabilidad
13/08/2026
Vulnerabilidad crítica de autenticación impropia (CVE-2026-59500) afecta múltiples productos
Se ha identificado una vulnerabilidad de severidad crítica (CVSS 10.0) en mecanismos de autenticación de múltiples fabricantes, permitiendo a atacantes eludir controles de acceso sin credenciales válidas. Esta falla afecta directamente infraestructuras críticas en México y Latinoamérica que dependen de sistemas de identificación y acceso. El impacto abarca compromisos totales de confidencialidad, integridad y disponibilidad en sistemas afectados.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59503] CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Per…
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59504] CWE-602: Client-Side Enforcement of Server-Side Security
CWE-602: Client-Side Enforcement of Server-Side Security
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59506] CWE-306: Missing Authentication for Critical Function
CWE-306: Missing Authentication for Critical Function
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59507] CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized…
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-15413] The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it …
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-14182] The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly val…
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49819] UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentica…
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers > 0` count check — a conditio…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-16770] PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in…
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through _pdf_webkit_meta_tags and turns each one into a wkhtmltopdf command line option. KEY is normalized to an option name matching --[…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-71193] In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the dupl…
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redire…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-49481] UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability …
UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be inserted into the wake_cmd and shutdown_cmd templates and executed via /bin/sh -c (Linux) or cmd /C (Windows) without sani…