Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1806
Esta semana
RSS
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-15300] The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'l…
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() before being interpolated into unquoted numeric positions in the proximity-search …
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-15282] The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing …
The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-14894] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Uplo…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separat…
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-54769] Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.…
Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an emp…
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-58122] Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthentic…
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overw…
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-58123] Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that al…
Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint to achieve full command execution as the server process…
P Crítico vulnerabilidad
09/07/2026
[CVE-2026-0284] An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PA…
An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-59726] Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-co…
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. …
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-59826] Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58…
Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection and execute arbitrary Java code on the Metabase server. This issue is fixed in vers…
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-59827] Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59…
Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without validation, allowing an authenticated user who can run native H2 queries to execu…
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-51597] MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTS…
MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-51599] An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build …
An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed …
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-13461] When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the Pay…
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-14261] A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution…
A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-12116] A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the to…
A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-5955] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-15158] The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up…
The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extens…
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-2342] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability i…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-14245] The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to A…
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the OTP validation step was completed, and relying solely on a public `form_nonce` no…
C Crítico vulnerabilidad
09/07/2026
[CVE-2026-47826] The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbi…
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.