Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 13 horas
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
13/08/2026
File Browser anterior a v2.63.22: bypass de controles de acceso en operaciones recursivas
File Browser versiones anteriores a la 2.63.22 presentan una vulnerabilidad de validación deficiente que permite a usuarios autenticados eludir controles de acceso basados en rutas durante operaciones de copia, renombre y eliminación recursiva. Un atacante interno puede manipular archivos denegados operando sobre directorios padre permitidos, comprometiendo el aislamiento por reglas y afectando confidencialidad e integridad de datos en servidores empresariales.
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad alta en ManageEngine Password Manager Pro y PAM360 permite eludir autenticación
ManageEngine Password Manager Pro (versiones anteriores a 13232) y PAM360 (versiones anteriores a 8551) presentan una vulnerabilidad de elusión de autenticación (CVSS 8.8) por validación incorrecta de SAML. Esto permite a atacantes acceder a gestores de credenciales sin autenticación válida, comprometiendo todas las contraseñas almacenadas en la solución. Afecta principalmente a empresas medianas y grandes en México y LATAM que utilizan estas herramientas para administración centralizada de accesos.
M Crítico vulnerabilidad
13/08/2026
Vulnerabilidad crítica de autenticación impropia (CVE-2026-59500) afecta múltiples productos
Se ha identificado una vulnerabilidad de severidad crítica (CVSS 10.0) en mecanismos de autenticación de múltiples fabricantes, permitiendo a atacantes eludir controles de acceso sin credenciales válidas. Esta falla afecta directamente infraestructuras críticas en México y Latinoamérica que dependen de sistemas de identificación y acceso. El impacto abarca compromisos totales de confidencialidad, integridad y disponibilidad en sistemas afectados.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59501] CWE-284: Improper Access Control
CWE-284: Improper Access Control
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59503] CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Per…
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59504] CWE-602: Client-Side Enforcement of Server-Side Security
CWE-602: Client-Side Enforcement of Server-Side Security
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59505] CWE-284: Improper Access Control
CWE-284: Improper Access Control

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59506] CWE-306: Missing Authentication for Critical Function
CWE-306: Missing Authentication for Critical Function
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-59507] CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized…
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
M Alto vulnerabilidad
13/08/2026
[CVE-2026-59499] CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19484] @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthent…
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry byte array, and a boundary of exactly 252 bytes makes the search needle 256 bytes, which truncates …
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-15413] The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it …
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except for the health check).
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19481] @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who ca…
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a plain JavaScript object and assumes each value is an array, so an inherited property name resolves …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-11840] Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions be…
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18146] The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin fo…
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Notification Smartcode Values in all versions up to, and including, 6.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in the…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18945] The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its…
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-14182] The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly val…
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-49473] @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Ce…
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain circumstances, the middleware matches incoming requests against Cedar action map…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49819] UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentica…
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token, IP allow-list, or rate limit and is gated only by a `totalSuperusers > 0` count check — a conditio…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-16770] PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in…
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through _pdf_webkit_meta_tags and turns each one into a wkhtmltopdf command line option. KEY is normalized to an option name matching --[…