Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 667 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-77770] The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does…
The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can lock every administrator out of the dashboard or deactivate every miniOrange 2FA WordPress plugin before 6.3.1, miniOran…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-19583] Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the…
Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS …
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-54694] SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code fl…
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that str…
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87526] Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker levera…
Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-75746] ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQ…
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-48273] ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('E…
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-82004] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69579] Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net…
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
Vulnerabilidad crítica en hawtio-operator expone claves de firma de OpenShift
Se encontró una flaw en hawtio-operator que permite la lectura no autorizada de la clave privada de firma de la autoridad certificadora (CA) de servicios de OpenShift desde el namespace openshift-service-ca. Un atacante con permisos de creación de recursos Hawtio en cualquier namespace puede falsificar certificados de cliente con CN arbitrario, escalando privilegios en clústeres OpenShift. Esta vulnerabilidad afecta directamente a empresas en LATAM que ejecutan plataformas de contenedores en OpenShift.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-66768] SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked fro…
SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and avai…
F Crítico vulnerabilidad
08/09/2026
JWT used for authentication in web GUI signed with static key
Fortinet PSIRT publica advisory de seguridad: JWT used for authentication in web GUI signed with static key. Tipo: Vulnerabilidad de seguridad. Producto afectado: Fortimonitor.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-86543] knowns versions before 0.30.0 serve the management API without authentication on all network interfa…
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-75650] Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engi…
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-76578] A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does…
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it add…
M Crítico vulnerabilidad
06/09/2026
Inyección de comandos OS crítica en Tenda HG10 (CVE-2026-86167)
Se identificó una vulnerabilidad crítica (CVSS 9.9) en el router Tenda HG10 modelo 300001138 que permite inyección de comandos del sistema operativo a través del parámetro fmgpon_loid en la función formgponConf. La vulnerabilidad es explotable remotamente y cuenta con exploits públicos disponibles. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos equipos en infraestructuras de acceso a internet.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-75816] The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Acco…
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as t…
M Crítico vulnerabilidad
05/09/2026
Vulnerabilidad crítica de autenticación en Lara Dashboard anterior a v1.3.0
Lara Dashboard versiones anteriores a 1.3.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en la ruta screenshot-login que permite a atacantes no autenticados acceder como cualquier usuario registrado mediante su correo electrónico cuando APP_ENV no está configurado en producción. Explotando el endpoint GET /screenshot-login/{email}, los atacantes obtienen sesiones completamente autenticadas con acceso a administración de usuarios, configuraciones y datos sensibles. Esta falla afecta principalmente a instancias de desarrollo y staging expuestas en entornos LATAM.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-13447] The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versio…
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT sig…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-19274] IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator coul…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlle…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-82923] The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or n…
The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory, and delete site content and media. On a host that serves PHP from the uploads di…