Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta de elusión de autenticación en Rodauth anterior a 2.46.0
Rodauth versiones anteriores a 2.46.0 contiene una vulnerabilidad de elusión de autenticación en la ruta webauthn_login que permite a usuarios autenticados suplantarse como otras cuentas. El defecto reside en la lógica impropia de resolución de cuentas que utiliza identificadores de sesión en lugar de validar correctamente el vínculo de credenciales, exponiendo sistemas que dependen de WebAuthn en México y LATAM a compromisos de cuentas no autorizados.
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76548] The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end fil…
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-17203] IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain …
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18891] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and a…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82329] JFrog Artifactory contains an authentication weakness that, under default configuration, may allow a…
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-73208] An attacker that holds a token intended for a different purpose can authenticate, because when an OA…
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be acc…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81202] A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function creat…
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-79938] Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnera…
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-78236] An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to a…
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19718] The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin Word…
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing att…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80192] @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 …
@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matchi…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79787] Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configurat…
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-24170] NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where a…
NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user could cause improper authentication by sending specially crafted HTTP requests. A successful exploit of this vulnerability might lead to code execution and escalation of privileges.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55533] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows …
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run requests despite authentication being enabled. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-77567] Filament is a collection of full-stack components for accelerated Laravel development. Prior to vers…
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-78167] A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function h…
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-78168] A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the fun…
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in a…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78154] A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function…
A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user_invitation_code.py of the component Public Invitation-Code Redemption Endpoint. The manipulation of the argument code leads to missing authentication. Remote exploitation of the attack is possible. The project was informed of the pro…
M Alto vulnerabilidad
20/08/2026
[CVE-2026-46355] BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu…
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse that participant's session and impersonate the participant in the same meeting b…
M Crítico vulnerabilidad
20/08/2026
[CVE-2026-17142] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary com…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.