Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-56154] Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:.…
Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-12627] Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability …
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-79898] Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user a…
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide network-accessible administration paths and do not require a local sudo or suexec r…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-62071] Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
Unauthenticated SQL Injection in WordPress File Upload
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103752] Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.
Unauthenticated Privilege Escalation in Authorizer
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-79901] In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Dire…
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
M Crítico vulnerabilidad
01/10/2026
Vulnerabilidad crítica de autenticación en Fleet versiones anteriores a 4.87.0
Fleet antes de la versión 4.87.0 contiene una vulnerabilidad de omisión de autenticación en la API de dispositivos que permite a atacantes no autenticados usar nombres de host o números de serie como tokens válidos. Los atacantes pueden acceder a datos de dispositivos iOS/iPadOS, instalar software malicioso e iniciar migraciones MDM. Esta vulnerabilidad afecta empresas en LATAM que gestionan flotas de dispositivos móviles corporativos.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103255] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security …
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103248] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filt…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103244] ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.res…
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-75957] The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable…
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `check…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-15989] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalatio…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role ag…
M Crítico vulnerabilidad
01/10/2026
[CVE-2025-41753] The object name of a dynamically created BACnet File Object is interpreted as a file path without su…
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-101148] The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its …
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The Backu…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-82829] Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability…
Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-92966] The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for Word…
The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbit…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-82824] Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that …
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-82825] Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critica…
Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects Hitachi Coding Software Suite: through 3.3.0.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-82827] Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Ke…
Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0.