Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,538
Total alertas
3074
Críticas
10192
Altas
8
Ransomware
1802
Esta semana
RSS
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-15039] The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of i…
The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.
M Crítico vulnerabilidad
12/08/2026
Vulnerabilidad crítica en Red Hat Advanced Cluster Management permite robo de tokens de clusters
Se identificó una falla en el componente multicloud-integrations de Red Hat Advanced Cluster Management (RHACM) que permite a usuarios autenticados manipular el controlador GitOpsCluster y redirigir tokens de bearer de clusters spoke hacia namespaces bajo su control. Esta vulnerabilidad (CVSS 9.6) afecta principalmente a empresas en LATAM con infraestructuras multicloud híbridas en Kubernetes, exponiendo credenciales críticas de acceso a recursos en la nube pública y privada.
M Crítico vulnerabilidad
12/08/2026
Vulnerabilidad crítica en multicloud-integrations permite ejecución de comandos en clusters Kubernetes
Se descubrió una falla en el componente multicloud-integrations que permite a un usuario con permisos de creación de Applications en el cluster hub explotar la validación deficiente de anotaciones para dirigirse a clusters Kubernetes arbitrarios. Un atacante podría forzar la sincronización maliciosa de ArgoCD en clusters spoke, comprometiendo la integridad de aplicaciones críticas en infraestructuras multi-nube. Este riesgo es crítico (CVSS 9.9) para empresas en LATAM que gestionan plataformas DevOps centralizadas.
F Crítico vulnerabilidad
12/08/2026
Broken access control in the RADIUS type admin group
Fortinet PSIRT publica advisory de seguridad: Broken access control in the RADIUS type admin group. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortiweb.
F Crítico vulnerabilidad
12/08/2026
Content-Encoding WAF Evasion
Fortinet PSIRT publica advisory de seguridad: Content-Encoding WAF Evasion. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortiweb.
F Crítico vulnerabilidad
12/08/2026
FGFM Authentication Weakening via CLI Configuration
Fortinet PSIRT publica advisory de seguridad: FGFM Authentication Weakening via CLI Configuration. Tipo: Bypass de Autenticación. Producto afectado: Fortigate.
F Crítico vulnerabilidad
12/08/2026
Heap overflow in kernel driver due to missing size validation
Fortinet PSIRT publica advisory de seguridad: Heap overflow in kernel driver due to missing size validation. Tipo: Desbordamiento de Heap. Producto afectado: Forticlient.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
F Crítico vulnerabilidad
12/08/2026
Stack buffer overflow in WAD
Fortinet PSIRT publica advisory de seguridad: Stack buffer overflow in WAD. Tipo: Desbordamiento de Búfer. Producto afectado: Fortios.
F Crítico vulnerabilidad
12/08/2026
UI DoS attack
Fortinet PSIRT publica advisory de seguridad: UI DoS attack. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortios.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-68067] The login endpoint on the Mira cloud API accepts any format-valid string in the password field and r…
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-67568] The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive heal…
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-5917] libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain…
libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing unescaped shell metacharacters such as single quotes, semicolons, or pipes. The gen_proto() function in ssh_libssh2.c inserts the repository …
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-66147] An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in G…
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48765] TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator …
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable `workspaceId`. The update path validates only the attacker-supplied workspace and then updates the c…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73032] PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to e…
PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt injection in PDFs, MITM interception of API requests, or a malicious custom LLM endpoint to execute arbitrary code in Zotero…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73034] DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers …
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipart upload request with a traversal-poisoned user_id header to escape the intended upload directory an…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-66145] An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044)…
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-45618] LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possi…
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-16230] The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insuffi…
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73211] PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.upda…
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.