Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-20315] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are …
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-20317] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Wo…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20317 are related to improper authentication issues that are …
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-20030] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20030 are related to improper neutralization of special elements us…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-71960] Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnera…
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate cr…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-53451] Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and…
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or parent-directory traversal an…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-52889] Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hi…
Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An unauthenticated attacker can place Twig syntax in one of these request-controlled inputs when…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-47187] SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue …
SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE for resolution by the client kernel against the local filesystem. The documented transform_symlinks mitigation does not contain relative targets because transform…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-16816] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-16656] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges …
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-15065] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security r…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-15068] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to exe…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-16019] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73388] Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Unauthenticated SQL Injection in Nikstore Core
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73389] Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated PHP Object Injection in Kalles Addons
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73390] Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
Unauthenticated Privilege Escalation in Total Donations

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73391] Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
Unauthenticated SQL Injection in Total Donations
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73347] Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Unauthenticated Privilege Escalation in TrueBooker
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73364] Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Customer PHP Object Injection in Flexible Subscriptions
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73183] Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Unauthenticated SQL Injection in Maps Marker Pro
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-73185] Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.