Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-86189] WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenti…
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the applicatio…
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-86190] WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns …
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal d…
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de autenticación en Lara Dashboard anterior a v1.3.0
Lara Dashboard versiones anteriores a 1.3.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en la ruta screenshot-login que permite a atacantes no autenticados acceder como cualquier usuario registrado mediante su correo electrónico cuando APP_ENV no está configurado en producción. Explotando el endpoint GET /screenshot-login/{email}, los atacantes obtienen sesiones completamente autenticadas con acceso a administración de usuarios, configuraciones y datos sensibles. Esta falla afecta principalmente a instancias de desarrollo y staging expuestas en entornos LATAM.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de inyección de objetos PHP en plugin Mail Mint para WordPress
El plugin Mail Mint (versiones hasta 1.31.0) para WordPress presenta una vulnerabilidad de inyección de objetos PHP (CVSS 9.8) que permite a atacantes no autenticados ejecutar código arbitrario mediante deserialización de datos no validados en la función 'handle_form_submission'. Afecta principalmente a tiendas WooCommerce y plataformas de email marketing en LATAM que utilizan este plugin.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica en Cua computer-server permite ejecución remota de comandos sin autenticación
Cua computer-server versiones anteriores a 0.3.42 omiten validación de autenticación cuando la variable de entorno CONTAINER_NAME no está configurada, exponiendo el puerto TCP 8000 a ataques no autenticados. Los atacantes pueden ejecutar comandos arbitrarios, acceder a sistemas de archivos y obtener shells interactivas en servidores empresariales en México y LATAM que utilicen esta versión vulnerable.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de ejecución remota sin autenticación en AutoAgent (CVE-2026-86124)
AutoAgent contiene una vulnerabilidad de ejecución remota de código sin autenticación en su servidor TCP que se vincula a todas las interfaces de red, permitiendo a atacantes ejecutar comandos bash arbitrarios como root. Los atacantes pueden conectarse al puerto expuesto y acceder a directorios del host montados en contenedores, comprometiendo completamente la confidencialidad, integridad y disponibilidad de la infraestructura. Esta vulnerabilidad afecta servidores en entornos containerizados comunes en empresas de LATAM.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica en plugin ComboBlocks para WordPress permite inyección de hooks sin autenticación
El plugin 'The Post Grid and Gutenberg Blocks – ComboBlocks' en versiones 2.2.32 a 2.3.1 es vulnerable a inyección de hooks no autenticada, permitiendo a atacantes ejecutar acciones maliciosas en WordPress sin credenciales. La vulnerabilidad afecta miles de sitios web en México y LATAM que utilizan este plugin para construcción de contenido con Gutenberg, exponiendo datos y funcionalidades críticas del sitio.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-83627] The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulner…
The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leadi…
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-13447] The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versio…
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT sig…
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-52766] YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki ac…
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any …
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75925] Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker…
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-81939] A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and arc…
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-78327] An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-78328] A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manage…
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75430] PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP…
PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-31020] In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to d…
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulner…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75431] PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-base…
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75160] An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via th…
An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-44402] Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in …
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-18658] IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.…
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.