Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3569 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
? Crítico alerta
31/08/2026
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Two Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-81578, CVE-2026-82078.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82616] A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUpl…
A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82593] A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /bo…
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
M Crítico vulnerabilidad
30/08/2026
[CVE-2026-82592] A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the f…
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
M Crítico vulnerabilidad
30/08/2026
[CVE-2026-82542] A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formI…
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
M Crítico vulnerabilidad
30/08/2026
Vulnerabilidad crítica en TOTOLINK A720R permite corrupción de memoria remota
Se identificó una vulnerabilidad de score CVSS 9.1 en el router TOTOLINK A720R versión 4.1.5cu.630_B20250509 que afecta la función setMacFilterRules del componente MAC Filtering. Un atacante remoto puede manipular el parámetro 'desc' para causar corrupción de memoria y potencial ejecución de código. El exploit ha sido divulgado públicamente, aumentando el riesgo inmediato para empresas en LATAM que utilizan este dispositivo en infraestructuras críticas.
M Crítico vulnerabilidad
30/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin MyHome Core para WordPress (CVE-2026-15980)
El plugin MyHome Core para WordPress versiones hasta 4.4.5 contiene una falla crítica (CVSS 9.8) que permite a atacantes no autenticados generar tokens de activación y obtener acceso válido a cuentas de usuario. La vulnerabilidad radica en la ausencia de validación de autorización en el manejador AJAX send_link() y validación inadecuada de tokens en la función activate(). Esta exposición afecta directamente a inmobiliarias, constructoras y empresas de servicios en LATAM que utilizan este plugin en sitios WordPress publicitarios o de gestión de propiedades.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/08/2026
Escalada de Privilegios Crítica en Plugin Custom User Registration Fields para WooCommerce (CVE-2026-15369)
El plugin Custom User Registration Fields para WooCommerce (versiones hasta 2.2.3) permite a atacantes no autenticados escalar privilegios mediante manipulación del parámetro afreg_select_user_role en la API /wc/store/v1/checkout. Esta vulnerabilidad afecta directamente tiendas en línea alojadas en servidores WordPress en México y LATAM, permitiendo que usuarios no autenticados asuman roles administrativos sin validación. El CVSS 9.8 indica riesgo crítico con alcance de red y sin requerimientos de autenticación.
M Crítico vulnerabilidad
29/08/2026
Vulnerabilidad crítica de directory traversal en Cloud Commander anterior a 19.20.2
Cloud Commander versiones anteriores a 19.20.2 contiene una vulnerabilidad de recorrido de directorios (directory traversal) en los endpoints REST de operaciones de archivo y markdown que permite a atacantes leer, escribir, mover o copiar archivos fuera del directorio raíz configurado. Esta vulnerabilidad afecta principalmente a empresas en LATAM que utilizan Cloud Commander para administración remota de servidores, exponiendo información sensible y permitiendo la modificación no autorizada de archivos críticos del sistema.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-82454] The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass i…
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which does not validate key/algorithm compatibility), an attacker can set alg=HS256 an…
M Crítico vulnerabilidad
29/08/2026
Vulnerabilidad crítica en argocd-mcp 0.8.0: exposición de interfaz HTTP sin autenticación
ArgoCD MCP versión 0.8.0 expone su transporte HTTP en todas las interfaces de red sin requerir credenciales cuando ARGOCD_API_TOKEN está configurado. Atacantes con acceso a la red pueden invocar la superficie completa de herramientas utilizando el token del operador para crear aplicaciones, ejecutar sincronizaciones y modificar recursos de Argo CD. Esta vulnerabilidad afecta crítica a infraestructuras de CI/CD en empresas que operan Kubernetes en LATAM.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-82448] Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that al…
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.
M Crítico vulnerabilidad
29/08/2026
Ejecución Remota de Código en Plugin Sigma Forms Pro para WordPress (CVE-2026-14494)
El plugin Sigma Forms Pro para WordPress (versiones hasta 1.4.5) es vulnerable a ejecución remota de código (RCE) mediante la función handle_form_submission. La vulnerabilidad permite a atacantes no autenticados subir archivos maliciosos al explotar la asignación dinámica de capacidades unfiltered_upload y el bypass de validación de tipos MIME. Afecta directamente a sitios WordPress en LATAM que utilizan este plugin para gestión de formularios sin parches.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-19286] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-19295] IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operatin…
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing …
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-18527] IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow…
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82277] Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operatio…
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55565] Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getV…
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompiler.cook instead of applying ValueExpression.escapeJavaString. The pattern can originate from POST /…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55634] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and …