Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
15/08/2026
Vulnerabilidad crítica de bypass de autenticación en plugin 6Storage Rentals para WordPress
El plugin 6Storage Rentals para WordPress (versiones hasta 2.27.0) contiene una vulnerabilidad crítica (CVSS 9.8) que permite a atacantes eludir la autenticación y acceder a cuentas de usuarios sin credenciales válidas. La falla reside en el manejador AJAX six_storage_create_wp_user() que se ejecuta sin validar tokens de seguridad, permisos ni propiedad de usuario, permitiendo la ejecución de funciones sensibles como wp_set_current_user() y wp_set_auth_cookie(). Afecta principalmente a sitios WordPress con comercio electrónico o alquileres en México y Latinoamérica.
M Crítico vulnerabilidad
15/08/2026
Vulnerabilidad crítica de bypass de autenticación en plugin User Session Synchronizer para WordPress (CVE-2026-15341)
El plugin User Session Synchronizer para WordPress en versiones hasta 1.4.0 contiene una vulnerabilidad de bypass de autenticación (CVSS 9.8) que permite la toma de control de cuentas sin validación de nonce, permisos o secretos compartidos. Un atacante puede explotar parámetros sin protección (`ussync-key`, `ussync-token`, `ussync-ref`) ejecutados en cada solicitud para secuestrar sesiones de usuarios, incluidas administrativas. Afecta directamente a medianas y grandes empresas en LATAM que alojan WordPress en infraestructura local o en la nube con este plugin activo.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-17175] IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti…
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-17182] IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and ob…
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-48528] Metacat is data repository software that helps researchers preserve, share, and discover data. Metac…
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input that can be passed through to the backend SQL database. The `nodeId` parameter can be modified to inject SQL commands, an…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-17099] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to im…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-17101] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensi…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73655] Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to…
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google's email_verified assertion. When existingEmailUser && !existingUser is true, the flow writes the ne…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-16867] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privi…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-17197] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to im…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.
M Crítico vulnerabilidad
13/08/2026
Vulnerabilidad crítica de autenticación impropia (CVE-2026-59500) afecta múltiples productos
Se ha identificado una vulnerabilidad de severidad crítica (CVSS 10.0) en mecanismos de autenticación de múltiples fabricantes, permitiendo a atacantes eludir controles de acceso sin credenciales válidas. Esta falla afecta directamente infraestructuras críticas en México y Latinoamérica que dependen de sistemas de identificación y acceso. El impacto abarca compromisos totales de confidencialidad, integridad y disponibilidad en sistemas afectados.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-14182] The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly val…
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered user who has not yet confirmed their email address.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73501] kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() i…
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI security requirement to be satisfied for unauthenticated requests when an application relies on Valida…
M Crítico vulnerabilidad
12/08/2026
[CVE-2024-27253] IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass secur…
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-11923] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-12359] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-42018] JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when an…
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-50561] Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platfor…
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — only performing a validity check. This allows an administrator token generated in another deployment ins…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-26035] An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through …
An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
M Alto vulnerabilidad
12/08/2026
Vulnerabilidad alta de autenticación en plugin WordPress Passwordless Login de VentraConnect
El plugin 'Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login' para WordPress (versiones hasta 1.4.3) contiene un fallo de autenticación que permite eludir el acceso mediante verificación insuficiente del correo electrónico devuelto por Spotify. Un atacante podría acceder a cuentas sin credenciales válidas. Afecta directamente a sitios WordPress en México y LATAM que implementen este plugin con autenticación social.