Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79746] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is used against a group route, isBearerKeyAllowedForRequest grants access to the entire group as long as any single server in that group appears in the key…
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta de omisión de autenticación en pac4j-core anterior a 6.5.6
pac4j-core antes de la versión 6.5.6 contiene una vulnerabilidad que invierte la lógica de validación de tipos de perfil en CheckProfileTypeAuthorizer, permitiendo a atacantes eludir controles de autenticación. Los agresores pueden autenticarse mediante clientes débiles y acceder a recursos que requieren perfiles más robustos al satisfacer validaciones genéricas. Afecta principalmente a aplicaciones Java en LATAM que dependen de esta librería para control de acceso.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-56854] The source-address critical option in the Permissions returned by an authentication callback was onl…
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-77438] Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.10…
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared notes. The endpoint authorizes only the ancestor note supplied in the request and…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77611] SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authent…
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access. The handler authorizes the request against the requested nested key but then writes the updated entry back to the bucket …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77317] SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, t…
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user granted access to /tenants/alice therefore also matches /tenants/alic…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80203] The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSup…
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the specific API key carries super authority (via isSuperWithinScope()). As a result, an API key scoped below full super auth…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80202] Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), wh…
Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently delete timesheets belonging to any user system-wide via the API, regardless of team …
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65182] Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security co…
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120, from 8.5.0 through 8.5.100, from 7.0.0 throu…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79218] Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker…
Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78911] Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who…
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-49050] General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinSch…
General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-56710] Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in th…
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71506] Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API del…
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accountin…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76836] AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not requi…
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in backend/src/Controller/Api/Stations/ProfileEditController.php deserializes with that group while requiring only StationPer…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-19685] NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path d…
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogu…
M Alto vulnerabilidad
21/08/2026
[CVE-2026-77234] Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-e…
Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this issue, users should upgrade to version 11.3.1 or later.
M Crítico vulnerabilidad
21/08/2026
[CVE-2026-62941] Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an ins…
Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration keys (including `security.privileged`, `raw.lxc`, `raw.apparmor`) from the source instance are merged AFTER the check pas…
M Crítico vulnerabilidad
20/08/2026
[CVE-2026-69555] Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne…
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.