Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1856
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19138] Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote att…
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19139] Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attac…
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19062] A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. …
A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument zuname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Ther…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-18367] A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos…
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16619] The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-facto…
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the one-time code without limit and take over the account.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16620] The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-si…
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the merchant-defined allowed prices and commit a real order at that price (revenue loss / underpriced orders). This is a distinct, unfi…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-17032] Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised…
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-14812] The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a h…
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-11976] The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) wa…
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retai…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-12584] The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the …
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own orders without paying.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13399] The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper autho…
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments
M Alto vulnerabilidad
06/08/2026
[CVE-2026-11803] A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read …
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-10524] The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the a…
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete WooCommerce orders at manipulated totals.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-10599] The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verif…
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark arbitrary orders as paid and bypass payment.
M Crítico vulnerabilidad
06/08/2026
[CVE-2025-14561] In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. Thi…
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-53977] OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remot…
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain. Attackers can exploit the route registration order in bootstrap-runtime.js to reach the shutdown ha…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-53985] Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Soc…
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can connect to the Socket.IO server on port 7000 without credentials due to disabled authentication enfor…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-3430] The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter befo…
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-43622] llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wr…
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger this memory management mismatch to cause denial of service through process crashes or potentially achieve arbitrary code …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18277] Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 2…
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path