Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
06/09/2026
[CVE-2026-18056] The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the acc…
The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without p…
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-75816] The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Acco…
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as t…
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de omisión de autenticación en Coolify hasta v4.3.17
Coolify versiones anteriores a 4.3.17 contiene una falla de autenticación en el manejador de callback OAuth que permite a atacantes registrar direcciones de correo de víctimas en proveedores OAuth habilitados para obtener acceso autenticado sin verificar identidades ni requerir contraseña. Empresas que usan Coolify como plataforma de infraestructura o despliegue en México y LATAM corren riesgo de compromiso de cuentas administrativas y acceso no autorizado a recursos altas.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-13447] The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versio…
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT sig…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85702] A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca92…
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-18221] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improp…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-83961] ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege es…
ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-82183] The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion retur…
The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary non-administrator user, and to create new accounts.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-12526] The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the reques…
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing ad…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84423] A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file …
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanat…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-76658] A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could a…
A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-76657] Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potenti…
Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-19806] The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin …
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit `…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82919] A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the func…
A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-61641] Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before …
Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email as verified (email_verified). When Wallos is configured against an IdP that lets a user present an arbitrary or unverifi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82693] A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function …
A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82694] A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSe…
A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82695] A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of th…
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-49003] Inyección de comandos crítica permite eliminación de archivos del sistema y escalada de privilegios
Vulnerabilidad crítica (CVSS 9.6) en múltiples plataformas permite a atacantes explotar inyección de comandos para eliminar archivos críticos del sistema operativo, provocando fallos en módulos de monitoreo. Los atacantes pueden obtener privilegios de root para robar credenciales SNMP y contraseñas de configuración, comprometiendo sistemas de control industrial y plantas energéticas en la región.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta de elusión de autenticación en plugin SAML SSO para WordPress (CVE-2026-75807)
El plugin SAML Single Sign On – SSO Login para WordPress (versiones ≤5.4.6) contiene una vulnerabilidad de elusión de autenticación que permite a atacantes validar certificados X.509 antes de completar la verificación de firma en la respuesta SAML. En LATAM, donde muchas empresas integran WordPress con sistemas de identidad corporativa SAML, esta falla expone credenciales y acceso no autorizado a portales internos, clientes y plataformas e-commerce.