Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 36 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
29/08/2026
[CVE-2026-82475] iFlytek astron-agent: vulnerabilidad de omisión de autorización en copyFlow
iFlytek astron-agent versión 1.1.1 y anteriores contiene una vulnerabilidad de omisión de validación de autorización en el endpoint copyFlow que permite a atacantes autenticados enumerar identificadores de flujos de trabajo y sobrescribir workflows de otros inquilinos o copiar definiciones privadas. El impacto es alta para entornos multitenante en plataformas cloud corporativas de LATAM que utilizan esta solución para automatización de procesos.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82279] HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, all…
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team member to perform administrative actions. Attackers can delete team members including owners, rotate API keys, and rename teams by sending requests to PATCH /team/apiKey, PATCH /team/name, and DELETE /team/member endpoints.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-56100] SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows au…
SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without authorization checks. Attackers can exploit the gateway's authentication filter, which only validates JWT parsing…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55521] Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks i…
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated low-privilege user can read packet and event index metadata without ObjectPrivilegeType.ReadPacket, alter COP-1 link state without…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-81767] Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Unauthenticated Broken Access Control in Simple Payment
M Alto vulnerabilidad
28/08/2026
CVE-2026-82245: Budibase anterior a 3.41.3 permite escalada de privilegios en gestión de licencias
Budibase versions anteriores a 3.41.3 no validan correctamente los roles de autorización en endpoints de gestión de licencias, permitiendo que usuarios autenticados eliminen claves de licencia y manipulen tokens offline. Atacantes con privilegios básicos pueden acceder a /api/global/license/* para desactivar funciones premium y degradar despliegues en toda la organización, afectando la disponibilidad de servicios altas en empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de escalada de privilegios en Budibase anterior a 3.41.3
Budibase versiones anteriores a 3.41.3 no valida correctamente las asignaciones de roles de constructor a nivel de aplicación en los endpoints públicos de creación y actualización de usuarios. Un constructor autenticado con acceso limitado a una aplicación puede explotar esta falla para otorgarse a sí mismo acceso de constructor en otras aplicaciones del mismo tenant, comprometiendo la segmentación de datos en entornos multi-tenant comunes en empresas medianas de LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de autorización en Budibase anterior a v3.41.3 permite inyección de recursos
Budibase versiones anteriores a 3.41.3 contienen una vulnerabilidad de autorización faltante en el endpoint POST /api/resources/duplicate que permite a constructores autenticados inyectar tablas, automatizaciones, consultas y pantallas en otras aplicaciones sin permisos en el espacio de trabajo destino. Un atacante puede especificar un ID de espacio de trabajo arbitrario en el cuerpo de la solicitud para comprometer la integridad de múltiples proyectos.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82239] Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/que…
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75813] Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthor…
Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75339] The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logge…
The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18965] PayRange API is missing proper authorization on management endpoints, which allows verbose details o…
PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with or without an account.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81335] Baserow dispatches an Application Builder data source without acting on the result of its permission…
Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permission class that admits any caller, so a request carrying no credential reaches the handler. DataSourceService.dispatch_data_sources in backend/src/baserow/contrib/bui…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-80433] Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Subscriber Sensitive Data Exposure in SureFeedback Client Site
M Alto vulnerabilidad
27/08/2026
[CVE-2026-27330] Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
Unauthenticated Broken Access Control in Mobile App for WooCommerce

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78137] The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on…
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81035] Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/t…
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access helper, which returns true for every row in the team-membership table irrespective of the role it records, and the data-layer function it calls re-checks the same helper and nothing else. The neighbouring procedures that remove or update a member in …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81027] one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a r…
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and otherwise rejects the caller, while the path-parameter branch sets the selected-channel value from c.Param("channelid") with no r…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-54569] SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.…
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many,…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-54523] Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1…
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace, resources) with an arbitrary target namespace. The validation in pkg/cel/policies/mpol/validate.go checks that the policy compile…