Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-59178] ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to v…
ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the bare `$USERNAME` and `$PASSWORD` instead. When the env vars were renamed the bare names were dropped with no fallback, so…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90944] Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication,…
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57131] PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts pr…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool c…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57124] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose PO…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. Because the UI commands bind to 0.0.0.0 by default, a reachable unauthenticated client can execute commands as the UI service …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57127] PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware…
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and ma…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57123] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57125] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the u…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a remote caller to cause a configured language model agent to invoke arbitrary operating…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90938] LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server…
LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by the upstream repository, Docker image, or docker-compose (which additionally publishes port 5401 to the host); the key check is therefore skipped entirely. Any remot…
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en Bifrost permite ejecución remota de código sin autenticación
Bifrost permite registrar clientes MCP a través de su API de gestión sin requerir handshake MCP ni autenticación cuando governance.auth_config.is_enabled=false (configuración por defecto). Un atacante puede ejecutar comandos arbitrarios como el usuario del proceso Bifrost mediante una única solicitud POST /api/mcp/client no autenticada, comprometiendo completamente servidores y gateways en empresas de LATAM que usen esta solución.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82787] Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerabil…
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90620] A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.…
A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling rel…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90579] A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the func…
A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early th…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90524] A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a…
A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a ro…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90504] A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae8641105…
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. T…
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-53952] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installatio…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-80462] A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthent…
A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de lectura de archivos sin autenticación en WWBN AVideo (CVE-2026-89250)
WWBN AVideo contiene una vulnerabilidad de lectura de archivos sin autenticación en el endpoint getRecordedFile.php que expone archivos de video grabados en FLV desde el directorio temporal. Atacantes pueden descargar archivos de video en vivo sin validación de autenticación utilizando claves de stream conocidas o adivinadas. Este riesgo afecta principalmente a plataformas de streaming y educación en línea en LATAM que utilizan esta solución para transmisiones en vivo.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de autenticación en WeenyGenius (CVE-2026-89176)
WeenyGenius, sistema de gestión de laboratorios informáticos de Howyar Technologies, presenta una vulnerabilidad de autenticación faltante (CVSS 8.8) que permite a atacantes en la misma red suplantar identidades de estudiantes o docentes sin credenciales. La suplantación de maestros compromete el control remoto de equipos estudiantiles, mientras que la de estudiantes interrumpe operaciones académicas normales. Instituciones educativas en México y LATAM con este software están expuestas en infraestructuras de redes cerradas o híbridas.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88018] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88285] Cámara GeoVision GV-LPC2211 V1.13 expone control PTZ sin autenticación
La cámara GeoVision GV-LPC2211 versión 1.13 expone un servicio de control PTZ (Pan-Tilt-Zoom) accesible por red sin requerir autenticación, permitiendo a atacantes remotos recuperar información de posicionamiento e inyectar comandos PTZ o comandos seriales arbitrarios. Esta vulnerabilidad afecta sistemas de vigilancia en infraestructura crítica, oficinas corporativas y centros de datos en México y Latinoamérica. Con CVSS 9.4, representa riesgo crítico de compromiso del perímetro de seguridad física y acceso no autorizado a sistemas de monitoreo.