Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta en better-auth SCIM permite control no autorizado de proveedores
Las versiones 1.5.0 a 1.7.0-beta.3 de better-auth SCIM presentan una falla de autorización que permite a usuarios autenticados gestionar proveedores SCIM creados por otros usuarios. Un atacante puede regenerar tokens bearer, invalidar tokens legítimos y autenticarse en rutas de API SCIM con tokens bajo su control. Este fallo afecta sistemas de identidad y acceso en empresas con infraestructura de autenticación centralizada.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-65981] Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using…
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quo…
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-17349] /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, wh…
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the stored credential fields password, save_password, and tunnel_password. When a non-owner triggered an adhoc connect against…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-68500] Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.…
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID t…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12945] IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other user…
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15658] A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to …
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-67348] Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoi…
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including task inputs, outputs, metadata, and temporal task tokens from other tenants.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-13178] The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts a…
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-60931] An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Globa…
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-57510] SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasSer…
SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas or queue UUIDs without organization scoping. Attackers can read cross-tenant execution history and event payloads contain…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-49258] Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and belo…
Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-operator CA scoping employed by the JSON API. This was partially addressed by GHSA-598g-h2vc-h5vg, but the changes were not implemented in the web read/mutation surface. Any authenticated non-admin operator (for example, one created via self-registration …
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59539] Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59546] Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Subscriber Broken Authentication in Hide My WP Ghost
M Alto vulnerabilidad
27/07/2026
[CVE-2026-17527] In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to p…
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source n…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-65708] sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allow…
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/07/2026
[CVE-2026-65709] sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JS…
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without Account…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-65710] sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authentica…
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the public link creation flow. Attackers can invoke the saveCreateFromAccountAction endpoint to cause AccountS…
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-15630] A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or mod…
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
M Alto vulnerabilidad
23/07/2026
[CVE-2026-47743] Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewir…
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to ta…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65917] CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDO…
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID th…