Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 9 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1790
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-77915] rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthentica…
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled. Attackers can register a new account that is immediately authenticated with Admin-level …
M Crítico vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-67602] phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows una…
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched column, enabling an entry written during an app_id lookup to satisfy a subsequent app_code lookup, allowing attackers to use…
M Crítico vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-59564] An authentication bypass issue exists in communications between affected versions of the Zscaler Cli…
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
M Crítico vulnerabilidad Nuevo
Hace 8 horas
Escalada de privilegios sin autenticación en Jawn <= 1.4.2 (CVSS 9.8)
Se ha identificado una vulnerabilidad crítica de escalada de privilegios sin autenticación en Jawn versión 1.4.2 y anteriores, con puntuación CVSS 9.8. Un atacante remoto puede explotar esta falla para obtener acceso administrativo sin credenciales válidas. Empresas en México y LATAM que utilicen Jawn en producción enfrentan riesgo inmediato de compromiso total del sistema.
M Crítico vulnerabilidad Nuevo
Hace 8 horas
Inyección de Objetos PHP sin autenticación en FreightCo <= 1.1.15
FreightCo versiones 1.1.15 y anteriores contienen una vulnerabilidad crítica (CVSS 9.8) que permite inyección de objetos PHP sin requerir autenticación. Esta falla afecta directamente a empresas logísticas y de transporte en LATAM que utilizan esta plataforma para gestión de cargas, permitiendo a atacantes ejecutar código arbitrario y comprometer completamente los sistemas. La ausencia de controles de autenticación previos amplifica significativamente el riesgo de explotación remota.
M Crítico vulnerabilidad Nuevo
Hace 8 horas
Vulnerabilidad crítica de inclusión de archivos en WP Cafe Pro < 3.0.15
Se ha identificado una vulnerabilidad de inclusión local de archivos (LFI) sin autenticación en WP Cafe Pro versiones anteriores a 3.0.15, con puntuación CVSS 9.8. Esta falla permite a atacantes remotos acceder a archivos sensibles del servidor, incluyendo configuraciones con credenciales de bases de datos. Afecta principalmente a tiendas en línea y sitios de comercio electrónico que utilizan este plugin en WordPress.
M Crítico vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-78167] A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function h…
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-78168] A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the fun…
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in a…
M Crítico vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-78169] A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the functio…
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.