Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1784
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
[CVE-2026-61982] Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65504] Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia
M Alto vulnerabilidad
06/08/2026
[CVE-2026-61961] Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
Unauthenticated Cross Site Scripting (XSS) in EmbedPress
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28183] Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
Editor Privilege Escalation in PublishPress Capabilities
M Alto vulnerabilidad
06/08/2026
[CVE-2026-34501] Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issu…
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-34502] Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This i…
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28172] Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28177] Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup Maker
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28111] Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Contributor Privilege Escalation in Forminator
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28140] Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Unauthenticated Broken Access Control in JetFormBuilder
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28141] Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28143] Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Forminator
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28082] Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine
M Alto vulnerabilidad
06/08/2026
[CVE-2025-49506] APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with re…
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16315] OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability …
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or un…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65551] Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Ac…
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66733] Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in Receiv…
Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by sending a crafted UDP packet with mUniquePacketID set to the maximum uint32 value. The mUniquePacketID field is read directly from the UDP wire-format packet header without bounds checking, cau…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19036] A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C…
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-68481] In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully…
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2…
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de inyección de comandos en Shibby Tomato 1.28.0000
Se identificó una vulnerabilidad de inyección de comandos del sistema operativo en Shibby Tomato 1.28.0000 a través del parámetro new_qoslimit_enable en la función new_qoslimit_start del archivo /etc/qoslimit. Esta falla permite a atacantes remotos ejecutar comandos arbitrarios con privilegios del router, afectando principalmente a empresas y proveedores de servicios en LATAM que utilizan este firmware en equipos de red altas. El exploit está disponible públicamente.