Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 436 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85663] Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods th…
Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85184] @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by m…
@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while the path-scoped middleware, such as aut…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85509] FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-f…
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85428] MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB…
MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS variables including actuator and override commands without authentication.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84238] Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versi…
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
M Crítico vulnerabilidad
01/09/2026
[CVE-2023-54391] Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in …
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-78012] An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-messa…
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51725] Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…
Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51730] Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…
Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51720] Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 a…
Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51679] Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows …
Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51680] Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unaut…
Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-51681] Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un…
Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
M Crítico vulnerabilidad
31/08/2026
ToolJet anterior a v3.16.208: Falla de validación de organizationId permite acceso no autorizado
ToolJet antes de la versión 3.16.208 no valida que el parámetro organizationId en las solicitudes de API coincida con el workspace autenticado del usuario. Un administrador de workspace puede crear, visualizar y eliminar tablas de base de datos en otros workspaces modificando el parámetro organizationId, comprometiendo la seguridad de datos en entornos multi-tenant críticos para empresas en LATAM.
M Crítico vulnerabilidad
29/08/2026
Escalada de Privilegios Crítica en Plugin Custom User Registration Fields para WooCommerce (CVE-2026-15369)
El plugin Custom User Registration Fields para WooCommerce (versiones hasta 2.2.3) permite a atacantes no autenticados escalar privilegios mediante manipulación del parámetro afreg_select_user_role en la API /wc/store/v1/checkout. Esta vulnerabilidad afecta directamente tiendas en línea alojadas en servidores WordPress en México y LATAM, permitiendo que usuarios no autenticados asuman roles administrativos sin validación. El CVSS 9.8 indica riesgo crítico con alcance de red y sin requerimientos de autenticación.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/08/2026
Vulnerabilidad crítica en argocd-mcp 0.8.0: exposición de interfaz HTTP sin autenticación
ArgoCD MCP versión 0.8.0 expone su transporte HTTP en todas las interfaces de red sin requerir credenciales cuando ARGOCD_API_TOKEN está configurado. Atacantes con acceso a la red pueden invocar la superficie completa de herramientas utilizando el token del operador para crear aplicaciones, ejecutar sincronizaciones y modificar recursos de Argo CD. Esta vulnerabilidad afecta crítica a infraestructuras de CI/CD en empresas que operan Kubernetes en LATAM.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-77012] The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its…
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied conten…
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16947] The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a …
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success respon…
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82266] Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t…
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.