Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1263
Esta semana
RSS
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77536] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77537] A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit…
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77539] A malicious actor with access to the network and high privileges could exploit an Improper Input Val…
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77540] A malicious actor with access to the network and high privileges could exploit an Improper Input Val…
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-59682] Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0…
Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80235] EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthe…
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77533] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-18431] The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and inclu…
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58095] mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for…
mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58096] LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the…
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
? Crítico alerta
26/08/2026
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Six Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2015-3246, CVE-2015-5287, CVE-2019-1068, CVE-2021-23758, CVE-2022-0995.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-19632] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw administrator password-reset URL — including the plaintext reset key and login parameters sto…
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de desbordamiento de búfer en TOTOLINK N600R 4.3.0cu.7647_B20210106
Se ha identificado una vulnerabilidad de desbordamiento de búfer en pila (stack-based buffer overflow) en el controlador CGI del router TOTOLINK N600R versión 4.3.0cu.7647_B20210106. La falla reside en la función setSystemConfig del archivo /cgi-bin/cstecgi.cgi y puede ser explotada remotamente manipulando el parámetro Hostname. Con CVSS 10.0, esta vulnerabilidad permite ejecución de código remoto sin autenticación y afecta a equipos de red en empresas, ISPs y centros de datos en toda Latinoamérica.
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica en ClipBucket V5: ejecución de comandos arbitrarios en instalador web
El instalador web de ClipBucket V5 no valida correctamente el parámetro php_cli_filepath, permitiendo que atacantes no autenticados ejecuten comandos arbitrarios con privilegios del servidor web mediante una solicitud POST maliciosa. Afecta principalmente a plataformas de video hosting y streaming implementadas en datacenters de LATAM sin actualizaciones de seguridad.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-16639] Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalizatio…
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65637] Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. …
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65905] Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, b…
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window.   This issue affects Apache Tomcat: …
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65182] Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security co…
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 throu…
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de traversal de directorios en DB-GPT permite ejecución de código remoto
DB-GPT construye rutas de destino para habilidades cargadas usando nombres de archivo sin validación, permitiendo ataques de traversal de directorios. Un atacante puede escribir archivos fuera del directorio designado e inyectar código malicioso. Afecta infraestructuras de IA/ML en empresas mexicanas y latinoamericanas que utilizan esta plataforma para procesamiento de datos.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79290] Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute …
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)