Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-52766] YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki ac…
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-82684] Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization …
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86090] ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipient…
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-86091] ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing …
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-63464] nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before v…
nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time, allow_private switches the dispatcher to an unguarded HTTP client, bypassing the priv…
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-78328] A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Manage…
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85651] Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operatio…
Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85512] A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vu…
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85433] MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing …
MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners on arbitrary addresses and redirect or duplicate bus traffic to attacker-controlled destinations.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-70178] Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a…
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85395] UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL…
UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85390] Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notificati…
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-63219] GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.…
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allows the upload of external uncontrolled files. An unauthenticated attacker can upload arbitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated attacker can write arbitrary files in…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84847] Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
Unauthenticated Broken Access Control in Quick Event Manager
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84779] Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 v…
Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84757] Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.
Unauthenticated Settings Change in WP Compress
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84238] Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versi…
Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-55658] Gardens v2 is a modular governance framework that enables communities to create and manage multiple …
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 per…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85212] CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServic…
CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85213] Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints…
Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and disable the server by putting the host out of rotation.