Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 10 horas
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad SSRF alta en Foxit PDF Services API permite acceso a archivos internos
La API de Foxit PDF Services contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) con puntuación CVSS 8.5 que permite a atacantes eludir validaciones mediante redirecciones URL y acceder a archivos locales y recursos internos. Empresas en México y LATAM que utilizan esta API para procesamiento de documentos PDF en aplicaciones web enfrentan riesgo de exposición de información sensible, credenciales y datos de configuración de servidores.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta en GStreamer gst-plugins-good permite denegación de servicio remota
Se encontró una falla en los componentes de depayload RTP (rtph264depay y rtph265depay) del paquete GStreamer gst-plugins-good que no valida límites máximos en el búfer de reensamblaje. Un atacante remoto sin autenticación puede enviar fragmentos RTP continuos sin marcadores de fin, agotando memoria y causando denegación de servicio en servidores multimedia, streaming en vivo y aplicaciones de videoconferencia operadas en infraestructuras en LATAM.
C Alto vulnerabilidad
06/08/2026
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
06/08/2026
CVE-2026-62869 Azure Entra ID Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62869 Azure Entra ID Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
06/08/2026
CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Medio vulnerabilidad
06/08/2026
CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad XSS almacenado alta en plugin TranslatePress para WordPress (CVE-2026-18510)
El plugin TranslatePress de WordPress presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en versiones hasta 3.2.6 que permite a atacantes sin autenticación inyectar código malicioso a través de comentarios con marcadores gettext codificados. La falta de sanitización de entrada y escapado de salida afecta directamente a sitios web multilingües en México y LATAM que dependen de este plugin para traducción de contenidos, comprometiendo la integridad y seguridad de visitantes y datos.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16268] The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing r…
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16734] The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the call…
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to change the amount of a payment intent that the Stripe Payment Forms by WP Full Pay …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18050] The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST r…
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to the uploader, and the file is removed on submission or by a scheduled cleanup, s…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-16054] The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not preven…
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13153] The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its…
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-13154] The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-suppl…
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-14829] The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin throug…
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPres…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-12713] The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a para…
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de SSRF en JeecgBoot hasta versión 3.9.2
Se identificó una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en JeecgBoot versiones hasta 3.9.2, específicamente en el componente Anonymous Chat Attachment Parser (/airag/chat/send). El defecto permite a atacantes remotos ejecutar solicitudes HTTP arbitrarias desde el servidor afectado, comprometiendo sistemas internos y datos sensibles. La vulnerabilidad tiene código de explotación público disponible, aumentando significativamente el riesgo para empresas LATAM que usan esta plataforma en producción.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de elusión de autenticación en plugin WPMU DEV Dashboard para WordPress
El plugin WPMU DEV Dashboard para WordPress (versiones hasta 5.0.0) contiene una vulnerabilidad de elusión de autenticación que afecta sitios no conectados al WPMU DEV Hub. La clave API del sitio permanece vacía en la configuración predeterminada, permitiendo falsificar firmas de solicitud WDP-AUTH. Esto expone a empresas mexicanas y latinoamericanas con sitios WordPress multisite a acceso no autorizado a funcionalidades administrativas altas.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18325] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16636] The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Pr…
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-15991] The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f…
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server, which can lead to remote code execution when the right file is deleted (such as …