Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 35 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-103956] Missing authentication for critical function in the authentication dependency in Loom for AWS before…
Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no …
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100291] In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process manageme…
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, several ONVIF service endpoints process management requests without enforcing required authentication. This could allow an unauthorized attacker to access sensitive device operations.
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-86246] Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled …
Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier unsupported versions may also be affected. Users are r…
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite ejecución remota sin autenticación (CVE-2026-57139)
PraisonAI versiones 1.5.0 a 1.7.2 contienen una falla de seguridad crítica (CVSS 9.8) en MCPServer.startHttp() que expone funciones de herramientas, recursos y prompts sin validación de autenticación. Cualquier cliente en red con acceso al puerto puede ejecutar comandos arbitrarios en sistemas que utilicen esta plataforma de agentes múltiples, afectando servidores en producción en México y Latinoamérica que procesen datos sensibles.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-57147] Vulnerabilidad crítica de autenticación en PraisonAI permite falsificación de tokens JWT
PraisonAI versiones anteriores a 0.1.6 contienen una vulnerabilidad de autenticación crítica (CVSS 9.8) donde la clave JWT_SECRET se asigna a un valor público conocido cuando las variables de entorno no están configuradas correctamente. Un atacante remoto no autenticado puede falsificar tokens JWT con identidades arbitrarias, comprometiendo sistemas multi-agente en producción. Afecta especialmente a empresas LATAM que implementan PraisonAI sin sobrescribir explícitamente las credenciales de desarrollo.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite falsificación de tokens JWT sin autenticación
PraisonAI versiones anteriores a 0.1.6 utiliza una clave HS256 predeterminada y pública cuando las variables de entorno no están configuradas, permitiendo que atacantes sin autenticación firmen tokens JWT arbitrarios. Esta falla afecta a sistemas que ejecuten plataformas de agentes multiequipo en configuraciones de desarrollo accidentalmente expuestas en producción, comprometiendo completamente el control de acceso.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57127] PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and ma…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-77915] rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthentica…
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled. Attackers can register a new account that is immediately authenticated with Admin-level …
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-67208] Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remo…
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute…
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-47668] DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner …
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed …
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-47393] PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that Praison…
PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by default. Users who follow the documented quickstart (`praisonai deploy --type api`) get a server that binds to `0.0.0.0` per the recommended sample YAML, exposes …
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-62415] Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Jo…
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-60024] Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Jo…
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
M Crítico vulnerabilidad
26/06/2026
[CVE-2026-46386] OpenProject is open-source, web-based project management software. Prior to , the official openproje…
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path reachable via the /my/two_factor_devices cookie reader This vulnerability is fix…
A Crítico vulnerabilidad
24/06/2026
[CVE-2026-55454] Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bund…
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is not directly published to the host by docker-compose.yml, it is reachable from the Appsmith server process itself or a SSRF vulnerability. An authentic…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-54067] SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body cont…
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing breaks out of its surrounding tag when renderSnippet() interpolates it via insertAdjacentHTML. A payload like runs arbitrary JavaScript in the renderer. On Electron desktop builds the renderer runs with nodeIntegration:true, so require('child_process') is reachable from the i…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-54158] SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (d…
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like or "> breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the vi…
M Crítico vulnerabilidad
22/06/2026
[CVE-2026-48509] MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless…
MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can…