Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-86520] Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time da…
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54767] WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controlle…
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafis…
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad de credenciales hardcodeadas en Dell OpenManage Server Administrator anterior a 11.1.0.3
Dell OpenManage Server Administrator en versiones anteriores a 11.1.0.3 contiene credenciales hardcodeadas que permiten acceso no autenticado remoto. Un atacante podría obtener acceso no autorizado a la consola de administración de servidores, comprometiendo la infraestructura alta. Afecta especialmente a centros de datos y empresas con servidores Dell en LATAM que utilicen esta herramienta sin actualizar.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92787] Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowin…
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-66890] The affected products use hard-coded credentials, which could allow remote access to files with root…
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-68950] The affected products use hard-coded credentials, which could allow an attacker to run the ftpd serv…
The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-16141] OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated…
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcR…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-57147] Vulnerabilidad crítica de autenticación en PraisonAI permite falsificación de tokens JWT
PraisonAI versiones anteriores a 0.1.6 contienen una vulnerabilidad de autenticación crítica (CVSS 9.8) donde la clave JWT_SECRET se asigna a un valor público conocido cuando las variables de entorno no están configuradas correctamente. Un atacante remoto no autenticado puede falsificar tokens JWT con identidades arbitrarias, comprometiendo sistemas multi-agente en producción. Afecta especialmente a empresas LATAM que implementan PraisonAI sin sobrescribir explícitamente las credenciales de desarrollo.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite falsificación de tokens JWT sin autenticación
PraisonAI versiones anteriores a 0.1.6 utiliza una clave HS256 predeterminada y pública cuando las variables de entorno no están configuradas, permitiendo que atacantes sin autenticación firmen tokens JWT arbitrarios. Esta falla afecta a sistemas que ejecuten plataformas de agentes multiequipo en configuraciones de desarrollo accidentalmente expuestas en producción, comprometiendo completamente el control de acceso.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90509] A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the fun…
A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early thr…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-75940] A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Ch…
A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.