Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1272
Esta semana
RSS
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-78657] The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletio…
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-9055] The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerab…
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when t…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84699] Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local ac…
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84352] Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attac…
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84353] Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a …
Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84354] Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attac…
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84333] Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attack…
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84324] Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute…
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84325] Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote a…
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84479] WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely o…
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84480] WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, al…
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84372] Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 un…
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF s…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75604] Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and…
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/…
M Crítico vulnerabilidad
01/09/2026
[CVE-2023-54391] Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in …
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-73749] Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malfo…
Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-76658] A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could a…
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-76657] Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potenti…
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-73700] A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow …
A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-73701] An unauthenticated remote code execution vulnerability exists in the underlying operating system of …
An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code as a privileged user on the underlying operating system, le…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-19766] An authentication bypass vulnerability exists in the underlying operating system of HPE Networking F…
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.