Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1275
Esta semana
RSS
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-79687] Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unau…
Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18931] Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Ind…
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-78012] An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-messa…
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18808] Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electr…
Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18210] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84119] Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed …
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84121] Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in…
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-51743] Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows…
Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-18765] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.
M Crítico vulnerabilidad
01/09/2026
Falla crítica en manejo de excepciones de Kyverno v1.9.0-v1.12.7 permite eludir políticas de seguridad
Kyverno versiones 1.9.0 a 1.12.7 contienen una vulnerabilidad en el procesamiento de excepciones de políticas que permite a atacantes eludir controles de seguridad. Cuando una política en modo enforce se combina con dos PolicyExceptions, la excepción menos restrictiva toma precedencia, permitiendo contravenir restricciones críticas mediante nombres de recursos diseñados. Esto afecta directamente a organizaciones en LATAM que dependen de Kyverno para governanza de Kubernetes en producción.
M Crítico vulnerabilidad
01/09/2026
Escalada de privilegios crítica en tema WordPress Nokri - Validación insuficiente de tokens
El tema WordPress Nokri Job Board contiene una vulnerabilidad de escalada de privilegios en versiones hasta 1.6.6 que permite a atacantes no autenticados tomar control de cuentas de usuario. La falla radica en validación deficiente de tokens de reinicio de contraseña en la función `nokri_reset_password()`, que acepta tokens vacíos coincidiendo con valores de metadata desconfigurados. Esto afecta directamente a empresas de LATAM que operan portales de empleo en WordPress, exponiendo bases de datos de candidatos y datos administrativos.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-83772] A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. Thi…
A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contact…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75865] The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode pl…
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attacker…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82971] A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown par…
A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer wi…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-83524] A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optim…
A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted ear…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82954] A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikCo…
A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82226] Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
Unauthenticated PHP Object Injection in Tickera
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-81780] Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
Unauthenticated Arbitrary File Upload in Hash Form
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-81763] Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.
Unauthenticated SQL Injection in Throws SPAM Away
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-81779] Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows …
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.