Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 36 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-49363] An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node detai…
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-49364] An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrativ…
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-57967] An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an exi…
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-67593] A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a qu…
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-49362] An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leadin…
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87922] A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9…
A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing authentication. The attack may be performed from remote. The exploit has been rele…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-77974] After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the …
After spoofing the device and obtaining one user confirmation, an attacker may be able to cause the application to transmit firmware through an unauthenticated and unsigned update channel.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86808] A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected elem…
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69528] Missing authentication for critical function in Windows Shell allows an authorized attacker to eleva…
Missing authentication for critical function in Windows Shell allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86727] AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php t…
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming creden…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86728] AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php…
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-62645] A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed …
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-86543] knowns versions before 0.30.0 serve the management API without authentication on all network interfa…
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86502] In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server a…
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-86480] In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service an…
In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/09/2026
[CVE-2026-79645] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-78480] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80132] ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.…
ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-76578] A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does…
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it add…
M Alto vulnerabilidad
07/09/2026
CVE-2026-86292: Autenticación ausente en SourceCodester Simple Traffic Offense System 1.0
Se detectó una vulnerabilidad de autenticación faltante en SourceCodester Simple Traffic Offense System 1.0 en el archivo saveuser.php (componente User Creation). Un atacante remoto puede manipular el parámetro position para crear usuarios sin credenciales válidas, comprometiendo la integridad de sistemas de gestión de infracciones de tránsito. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo alto para municipalidades y autoridades viales en LATAM que usan esta plataforma.