Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 23 min
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de inyección de comandos en Totolik A3002MU
Se ha identificado una debilidad en el enrutador Totolik A3002MU versión Hh-B20211125.1046 que permite inyección de comandos remotos a través del parámetro localPin en la función formWsc del archivo /boafrm/formWsc. La vulnerabilidad tiene puntuación CVSS 9.9 (crítica) y ya cuenta con exploits públicamente disponibles, exponiendo a empresas en LATAM que utilizan este dispositivo a acceso no autorizado e infiltración de redes.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-86591] The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its…
The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allowing unauthenticated users to update arbitrary WordPress options with arbitrary values, which could lead to privilege escalation and a full site takeover. The same route also allows unauthenticated users to store arbitrary web scripts which are then executed on every page of the si…
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de desbordamiento de búfer en router Totolink A3002MU
Se ha descubierto una falla de seguridad crítica (CVSS 10.0) en el router Totolik A3002MU versión Hh-B20211125.1046 que permite desbordamiento de búfer remoto a través del parámetro submit-url en la función formWlWds. El exploit está disponible públicamente, aumentando significativamente el riesgo de compromiso en infraestructuras de pequeñas y medianas empresas en Latinoamérica que utilizan este dispositivo como gateway de red.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica en plugin Forminator para WordPress permite ejecución arbitraria de shortcodes
El plugin Forminator Forms para WordPress (versiones hasta 1.57.2) es vulnerable a ejecución arbitraria de shortcodes debido a validación insuficiente en la función do_shortcode. Atacantes no autenticados pueden ejecutar código malicioso en sitios web afectados, comprometiendo la integridad de formularios de contacto y pago. Esta vulnerabilidad impacta directamente a empresas en LATAM que utilizan este plugin en formularios críticos de recolección de datos y procesamiento de pagos.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica en WP Recipe Maker: ejecución arbitraria de shortcodes en WordPress
El plugin WP Recipe Maker para WordPress (versiones hasta 10.8.1) permite la ejecución arbitraria de shortcodes a través del campo reviewBody en metadatos de recetas. Un atacante puede inyectar código malicioso mediante comentarios que se procesan sin sanitización adecuada, comprometiendo sitios web de empresas, blogs corporativos y plataformas de contenido culinario en LATAM. El impacto afecta la integridad del contenido y puede derivar en acceso no autorizado a datos sensibles.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica de carga arbitraria de archivos en Gravity Forms para WordPress (CVE-2026-84434)
El plugin Gravity Forms para WordPress es vulnerable a carga arbitraria de archivos en versiones hasta 3.1.0.4. Un defecto en la validación de extensiones permite eludir controles de seguridad en campos ocultos de carga, exponiendo servidores a ejecución de código remoto. Afecta principalmente a empresas, agencias digitales y e-commerce en LATAM que dependen de formularios de contacto y recopilación de datos en WordPress.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75885] A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/d…
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests withou…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93739] A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function form…
A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93740] A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formW…
A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93738] A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSched…
A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93839] LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket…
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to int…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84075] IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due …
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84078] IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the Loa…
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions and impact to the integrity and availability of the affected system.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84082] IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands du…
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84031] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84064] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary S…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84073] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary S…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-82967] IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthent…
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interface.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-82340] IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and atta…
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network attacker able to reach TCP port 16017 may submit crafted serialized messages and potentially cause unintended code execution in the Guardium appliance.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-82832] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.