Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
Plugin Security Hardener para WordPress vulnerable a falta de autorización en versiones hasta 2.4.4
El plugin Security Hardener para WordPress contiene una vulnerabilidad de autorización faltante (CVE-2026-16149, CVSS 8.8) en todas las versiones hasta la 2.4.4. La función de protección contra enumeración de usuarios, habilitada por defecto, modifica incorrectamente los permisos en los endpoints /wp/v2/users y /wp/v2/users/, permitiendo acceso no autorizado a información sensible. Este riesgo afecta directamente a sitios de e-commerce, portales corporativos y aplicaciones con datos altas en LATAM que dependen de esta funcionalidad.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad alta en plugin WPeMatico permite escalada de privilegios en WordPress
El plugin WPeMatico RSS Feed Fetcher para WordPress (versiones hasta 2.8.24) contiene una falla de validación de permisos en la función wpematico_import_settings que permite a usuarios autenticados con acceso de suscriptor modificar opciones arbitrarias del sitio. Esta vulnerabilidad (CVSS 8.8) afecta principalmente a medianas y pequeñas empresas en LATAM que usan WordPress para gestión de contenidos y están expuestas a ataques internos o compromiso de cuentas de bajo privilegio.
M Alto vulnerabilidad
Hace 2 días
Escalada de privilegios alta en LeafWiki versiones 0.1.0 a 0.10.0 (CVE-2026-53527)
LeafWiki, plataforma wiki autohospedada, contiene una vulnerabilidad de escalada de privilegios (CVSS 8.8) en su API de actualización de usuarios. Un atacante autenticado puede modificar su rol y escalar permisos de usuario regular a administrador, comprometiendo el control de acceso de la instancia. El riesgo es alta para empresas en LATAM que usan LeafWiki como repositorio interno de conocimiento sin restricciones de registro público.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-75796] The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized …
The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account on the network, including the Network Administrator's.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-17145] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-16991] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper handling of symbolic links.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-16997] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary comm…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper privilege management.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-16937] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-16923] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-75860] The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verifica…
The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every request and is available to unauthenticated users, allowing them to update arbitrary WordPress options. This can be leveraged to enable user registration and set the default role to administrator, leading to privilege escalation and full site takeover.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76396] In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capabil…
In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/e…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76350] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could configure Portable Document Format (PDF) attachments in the email alert action workflow. When the email alert action runs, it could execute arbitrary Search Processing Language (SPL) commands with system-level privileges, expose all relevant data, and affect sy…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76253] In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role wit…
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and ava…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76259] In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local …
In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user account running Splunk Enterprise. The vulnera…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-68561] Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) ru…
Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included sort. Because Meteor combines allow rules with OR semantics and applies the complete modifier, a comment-only or read-only member could send one Boards.…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16874] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain root privileges due to improper enforcement of RBAC authentication roles.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16850] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command injection via crafted Router Advertisements.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16703] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileg…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-70421] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulne…
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-75924] A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole …
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to information disclosure and privilege escalation within the cluster.