Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 2323 resultados ✕ Limpiar búsqueda
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-63077] In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible …
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-17191] An input validation vulnerability exists in an API component of the orchestrator. An authenticated u…
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not awa…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-66395] SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar p…
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.
M Crítico vulnerabilidad
27/07/2026
[CVE-2025-50455] SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Al…
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-65879] Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret …
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-61511] vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB…
vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. Attackers can exploit the insufficiently restrictive regex filter by using phpfuck-style …
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-55971] Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache T…
Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-58023] Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift…
Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-58662] Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrif…
Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-48144] Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings…
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-64534] In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED be…
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_liv…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-64535] In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF wh…
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which p…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13597] The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its …
The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an a…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13714] The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate th…
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve rem…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-14289] The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one…
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13332] The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unaut…
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.
M Crítico vulnerabilidad
26/07/2026
[CVE-2026-64530] In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_A…
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act_ct on out-of-order fragments). When that happens the skb is no longer owned by the caller and must not be touched again. tcf_qevent_handle() did not handle TC_AC…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-66012] SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint…
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publis…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64523] In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-live…
In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submit handshake_nl_accept_doit() needs the file pointer backing req->hr_sk->sk_socket to survive the window between handshake_req_next() and the subsequent FD_PREPARE() and get_file(). The submit-side sock_hold() does not provide that. sk_refcnt keeps struct sock alive, but st…
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-64459] In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period i…
In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU") removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that "the destruction of info/keys is delayed until the socket destructor" and therefore "no one can discover it anymore". That argument …