Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en Thinkware U3000 permite acceso no autorizado remoto
Se identificó una vulnerabilidad (CVSS 7.3) en Thinkware U3000 versiones hasta 1.02.04 que afecta la función PUT_FILE en el archivo /tmp/wpa_supplicant.conf del servicio TCP. Un atacante remoto puede manipular parámetros de ruta para eludir controles de acceso. La vulnerabilidad ha sido divulgada públicamente y cuenta con exploits disponibles, aumentando el riesgo inmediato para organizaciones en LATAM que usan esta plataforma en dispositivos de conectividad empresarial.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-88421] Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0…
Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the sidebar widgets, or the RSS feed.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-85057] ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL …
ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action author with ORG_OWNER, org.action.write, and org.flow.write permissions can run JavaScript at OIDC, SAML, and login-flow trigger points and load files readable by t…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96513] A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown p…
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, a…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95500] A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted …
A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95499] A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects…
A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-94036] A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. Th…
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87839] The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate…
The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-58197] ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol s…
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docker.internal while ToolHive API and MCP proxy endpoints are reachable without authentication. A malici…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93604] vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embed…
vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The builtin sanitizer (sanitizeCryptoModule in lib/builtin.js) replaces crypto.setEngine but leaves crypto.setFips callable, and the readonly wrapper used to expose the host module does not localize side effects…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-90978] The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX ha…
The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonce field is omitted, and applies no capability check, allowing low-privileged users to overwrite the content of arbitrary posts and delete the Filter Gallery WordPress plugin before 1.1.5's stored gallery options.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-83944] Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges ov…
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20332] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Ad…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20322] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Das…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20322 are related to improper access control issues that…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20192] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CV…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-63695] Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerabilit…
Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-65362] This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Se…
This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-64712] This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Se…
This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-19290] IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allo…
IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54628] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A remote attacker can provide a loopback, private-network, or link-local cloud metadata URL, causing go-getter in the Anyquery s…