Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad de inyección SQL en Mautic afecta gestión de contactos
Mautic presenta una vulnerabilidad alta (CVSS 7.1) en el controlador AjaxController donde el parámetro 'field' no se valida correctamente antes de ser usado como identificador SQL directo. Un atacante autenticado podría ejecutar consultas SQL arbitrarias para acceder, modificar o exfiltrar datos de contactos (leads) en sistemas que usan esta plataforma de marketing automation, común en empresas medianas y agencias de LATAM.
M Crítico vulnerabilidad
05/08/2026
Inyección SQL crítica en Inventory-Management-System-PHP permite bypass de autenticación
El sistema de gestión de inventario PHP contiene vulnerabilidades de inyección SQL en los módulos login.php y delete.php debido a la concatenación insegura de parámetros POST sin validación ni uso de consultas parametrizadas. Un atacante puede ejecutar consultas arbitrarias, eludir la autenticación y manipular datos de inventario críticos en sistemas empresariales de LATAM que dependen de este software.
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad alta de autenticación en Documize Community permite acceso no autorizado a archivos
Documize Community contiene una falla de autenticación en su ruta de descarga de adjuntos que permite a atacantes eludir completamente la autenticación usando cualquier valor no vacío en el parámetro 'secure'. Esto expone documentos y archivos confidenciales en empresas que utilizan esta plataforma para gestión de contenido. Con CVSS 7.5, afecta significativamente la confidencialidad de datos en organizaciones mexicanas y latinoamericanas que almacenan información sensible en Documize.
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad alta en Magistrala: Motor de reglas permite ejecución remota de código
El motor de reglas de Magistrala permite a usuarios autenticados crear reglas con scripts Go o Lua que se ejecutan en el servidor cuando llegan mensajes IoT. El intérprete Yaegi expone la librería estándar de Go completa (incluidos módulos os y net/http), permitiendo a atacantes autenticados ejecutar código arbitrario con acceso al sistema operativo. Esta vulnerabilidad afecta altas despliegues IoT en manufactura, utility y ciudades inteligentes en LATAM.
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad alta en Grocy: inyección XSS a través de parser de solicitudes API
Grocy presenta una vulnerabilidad de inyección de scripts (XSS) en su analizador de solicitudes API (BaseApiController.php) que permite a atacantes eludir la purificación HTML mediante decodificación doble de entidades. Un adversario podría inyectar código malicioso que se ejecute en el contexto de aplicaciones que gestionen inventarios y despensas, comprometiendo datos sensibles de empresas pequeñas y medianas en México y LATAM que utilizan este software de código abierto.
M Crítico vulnerabilidad
05/08/2026
Inyección SQL crítica en Miantang/IoT-PHP permite autenticación sin credenciales válidas
La aplicación Miantang/IoT-PHP contiene una vulnerabilidad de inyección SQL en la ruta POST /userlogin debido a que no sanitiza el parámetro de contraseña antes de concatenarlo en una consulta SQL raw. Un atacante puede eludir la autenticación ingresando caracteres especiales en el campo de contraseña. Esta vulnerabilidad afecta sistemas IoT y aplicaciones embebidas en infraestructuras críticas de LATAM, permitiendo acceso no autorizado a datos sensibles y control del dispositivo.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71238] DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py ra…
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid session cookies (including for the superadmin account), forge CSRF tokens, and forge password reset tokens…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71239] DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Dja…
DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template() constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content directly into a Template() call; email_creators.py passes eml_message.subject directly as a template string to Template(); and helpers.py c…
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad alta en Book-Management-System: endpoints Flask exponen datos de estudiantes sin autenticación
Los endpoints /student, /record, /books, /find_stu_book y /find_not_return_book carecen del decorador @login_required, permitiendo acceso no autenticado a información personal de estudiantes (nombre, género, estado de carné, deuda) e historial completo de préstamos mediante suministro de card_id. Afecta instituciones educativas y bibliotecas en LATAM que utilizan este sistema de gestión.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-60009] In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /f…
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection toke…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-66747] Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every pub…
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-71231] IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM …
IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='' after base64-decoding the client-supplied lastLogin cookie via safe_decode(), which performs URL-safe base64 decoding with no sanitization of the decoded value before it is concatenated into the SQL string. An unauthenticated attacker can set a lastLogin c…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71232] MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP fu…
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log. Combined with ThinkPHP's {if} template tag, which embeds the condition attribute directly into raw PHP …
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71233] InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Larave…
InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! $entity->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization. StoreInvoiceRequest.php only strips newlines from the field and does not purify HTML. An authenticated user with invoice creation access can set the t…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-12609] In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend expo…
In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path stays within the plugin's directory. An unauthenticated network attacker can send percent-encoded `../` sequences (`%2e%2…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-25703] NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to m…
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-44945] A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests…
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-10090] A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of…
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies t…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-10059] A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant admin…
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalatio…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7444] The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via …