Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-84738] The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through…
The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, leading to Remote Code Execution.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93467] The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote…
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-85878] Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate pri…
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-69843] Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate pri…
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-62874] Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to e…
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-85885] Improper neutralization of special elements used in a command ('command injection') in M365 Copilot …
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-85889] Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to …
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-87701] Improper neutralization of special elements in output used by a downstream component ('injection') i…
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-83944] Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges ov…
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-77903] Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate …
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-70200] Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a…
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-70009] Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows a…
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-69865] Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthori…
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-69399] Azure Arc Elevation of Privilege Vulnerability
Azure Arc Elevation of Privilege Vulnerability
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54734] Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters in…
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54767] WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controlle…
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafis…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54670] WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatc…
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical dire…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54460] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind enrollment to locals.user.id. An unauthenticated attacker who knows the public tenant ID a…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-45140] Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unau…
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, component, input, or exploitation mechanism. This issue is fixed in version 2.0.1.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-45143] Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo…
Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue and public/main/template/default/message/view_message.html.twig. An authenticated low-privilege user, including a student, can directly address crafted message cont…