Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57123] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57125] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the u…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating…
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en Bifrost permite ejecución remota de código sin autenticación
Bifrost permite registrar clientes MCP a través de su API de gestión sin requerir handshake MCP ni autenticación cuando governance.auth_config.is_enabled=false (configuración por defecto). Un atacante puede ejecutar comandos arbitrarios como el usuario del proceso Bifrost mediante una única solicitud POST /api/mcp/client no autenticada, comprometiendo completamente servidores y gateways en empresas de LATAM que usen esta solución.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82787] Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerabil…
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-53952] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installatio…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-80462] A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthent…
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88018] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88285] Cámara GeoVision GV-LPC2211 V1.13 expone control PTZ sin autenticación
La cámara GeoVision GV-LPC2211 versión 1.13 expone un servicio de control PTZ (Pan-Tilt-Zoom) accesible por red sin requerir autenticación, permitiendo a atacantes remotos recuperar información de posicionamiento e inyectar comandos PTZ o comandos seriales arbitrarios. Esta vulnerabilidad afecta sistemas de vigilancia en infraestructura crítica, oficinas corporativas y centros de datos en México y Latinoamérica. Con CVSS 9.4, representa riesgo crítico de compromiso del perímetro de seguridad física y acceso no autorizado a sistemas de monitoreo.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-49364] An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrativ…
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-57967] An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an exi…
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-67593] A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a qu…
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes …
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-62645] A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed …
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-86543] knowns versions before 0.30.0 serve the management API without authentication on all network interfa…
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-86480] In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service an…
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-76578] A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does…
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it add…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de autenticación en Lara Dashboard anterior a v1.3.0
Lara Dashboard versiones anteriores a 1.3.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en la ruta screenshot-login que permite a atacantes no autenticados acceder como cualquier usuario registrado mediante su correo electrónico cuando APP_ENV no está configurado en producción. Explotando el endpoint GET /screenshot-login/{email}, los atacantes obtienen sesiones completamente autenticadas con acceso a administración de usuarios, configuraciones y datos sensibles. Esta falla afecta principalmente a instancias de desarrollo y staging expuestas en entornos LATAM.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica en Cua computer-server permite ejecución remota de comandos sin autenticación
Cua computer-server versiones anteriores a 0.3.42 omiten validación de autenticación cuando la variable de entorno CONTAINER_NAME no está configurada, exponiendo el puerto TCP 8000 a ataques no autenticados. Los atacantes pueden ejecutar comandos arbitrarios, acceder a sistemas de archivos y obtener shells interactivas en servidores empresariales en México y LATAM que utilicen esta versión vulnerable.
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de ejecución remota sin autenticación en AutoAgent (CVE-2026-86124)
AutoAgent contiene una vulnerabilidad de ejecución remota de código sin autenticación en su servidor TCP que se vincula a todas las interfaces de red, permitiendo a atacantes ejecutar comandos bash arbitrarios como root. Los atacantes pueden conectarse al puerto expuesto y acceder a directorios del host montados en contenedores, comprometiendo completamente la confidencialidad, integridad y disponibilidad de la infraestructura. Esta vulnerabilidad afecta servidores en entornos containerizados comunes en empresas de LATAM.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85695] FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allow…
FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85688] TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the …
TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.