Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 7 min
Buscando: "Quest" — 32 resultados ✕ Limpiar búsqueda
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1740
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-78169] A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the functio…
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Crítico vulnerabilidad
Hace 2 días
Vulnerabilidad crítica SSRF en plugin Mailgun para WordPress permite acceso no autorizado
El plugin Mailgun for WordPress versiones hasta 2.2.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) por validación insuficiente en la función add_list(). Atacantes no autenticados pueden explotar el path traversal mediante claves controladas en $_POST['addresses'] para acceder a recursos internos del servidor. Afecta directamente a sitios WordPress en México y LATAM que utilizan este plugin para gestión de correos transaccionales.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-61539] Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and …
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a tools field flow through xinference/api/restful_api.py, xinference/model/llm/transfor…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-77087] Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attack…
Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to make authenticated API requests and execute commands through the process adapter.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-62941] Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an ins…
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the source instance are merged AFTER the check pas…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-77806] SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited i…
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
M Crítico vulnerabilidad
Hace 3 días
Vulnerabilidad crítica en proxy LLM de Headroom permite suplantación de usuarios
Headroom's LLM proxy contiene una vulnerabilidad de autenticación insuficiente (CVSS 9.1) en el encabezado x-headroom-user-id que permite a atacantes acceder y modificar datos de memoria de otros usuarios sin autorización. El fallo afecta rutas de chat completion y websocket en headroom/proxy/handlers/openai.py. Empresas que usan este proxy para gestionar modelos de lenguaje corren riesgo de exposición de datos sensibles y suplantación de identidad.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
Vulnerabilidad crítica de autenticación en plugins de WordPress para WooCommerce (CVE-2026-77264)
El plugin 'Automation Web Platform – Notifications and OTP for WooCommerce' y el complemento 'Advanced Country Code' para WordPress presentan un bypass de autenticación en versiones hasta 4.8.6. La función handle_email_otp_return() expone el token de login secreto en respuestas públicas de solicitudes OTP, permitiendo acceso no autorizado sin validación de correo. Afecta directamente a tiendas en línea, plataformas de e-commerce y sitios con autenticación de dos factores basada en OTP en México y Latinoamérica.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69851] Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat…
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65801] Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-71485] Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies …
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The requestHeaders path in internal/proxy/http.go, the requestMetadata path in internal/proxy/grpc.go, and the Consume path in in…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-73256] Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated atta…
Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible greater-than-eight condition even though mg_http_parse() requires an eight-byte protocol stri…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-73257] Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthentica…
Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and prioritize chunked encoding, while a Content-Length-preferring reverse proxy can use …
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-55642] dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in c…
dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no stored password exists, while crates/dbx-web/src/main.rs binds the service to 0.0.0.0 on port 4224 by default. An unauthen…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-28164] Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Sit…
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-75860] The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica…
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-76850] LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine…
LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the isinstance check against DistServeCacheFreeRequest runs only after deserialization has already completed. The peer that supplie…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-53548] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password or field=sudoPassword query without enforcing host ownership during credential resolution. A failed requester-scoped loo…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-53546] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that host without requiring ownership or explicit access. When no credential is shared with the requester, resolveHostById performs an owner credential fallback, and…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-63722] ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthentic…
ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP POST request to the terminal endpoint with a password parameter to bypass authentication, a non-empty csrf parameter to sk…