Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-62941] Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an ins…
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the source instance are merged AFTER the check pas…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69555] Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne…
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-55089] Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/AP…
Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/OAuth2Provider.ts issues admin: false for configured non-admin users. A non-admin user with a valid s…
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-71424] Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers …
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in backend/onyx/server/features/mcp/api.py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_se…
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-66792] A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a use…
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the elevated permissions of the controller's Service Account, potentially leading to …
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-19598] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalatio…
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-71193] In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the dupl…
In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter scheduler, creating an overlapping zone that conflicts with another tenant's zone. This enables cross-tenant DNS hijack (redire…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-63296] An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target proje…
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privile…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-63297] An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allow…
An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can …
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-62420] An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target proje…
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: , and target: , the destination node skips all project restriction checks because the r…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73090] PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity…
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a malicious federated server to rewrite another server's video metadata, visibility, media file, and HLS URLs. This issue is fixed …
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-71398] Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu…
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-71362] Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privileg…
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-27302] Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu…
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-71384] is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypa…
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this is…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-72886] Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.c…
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive serviceId from applicationId or composeId and execute the owner/admin host-schedule gate only in the alternative branch, allowing a member with access to one application to attach its applicationId to a dokploy-server sc…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-52466] Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The appl…
Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not allow access to the requested function. The requester receives a response indicating that access was denied, but the act…
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-48333] Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could resu…
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica en ArcadeDB anterior a 26.7.2 permite ejecución arbitraria de código JavaScript
ArcadeDB versiones anteriores a 26.7.2 no validan correctamente permisos de scripting en sentencias SQL DEFINE FUNCTION con lenguaje JavaScript, permitiendo que usuarios con acceso a la base de datos ejecuten código malicioso y eludir controles de seguridad. Este fallo afecta principalmente a empresas en LATAM que utilizan ArcadeDB para aplicaciones críticas sin actualizar regularmente. El CVSS 9.8 indica riesgo crítico que requiere atención inmediata.