Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100708] Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key con…
Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are passed through ApiCommand::response() without any field stripping or allowlist. A low-privileged authenticated customer API calle…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100703] Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment …
Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, http.Lib, configMap loader) which are handed the policy namespace. A tenant who can create a namespaced policy (e.g. NamespacedValidatingPolicy, and likewise the namespaced mutating, deleting, generating, and…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100680] Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Sw…
Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate sensitive files including environment variables containing JWT secrets, API keys,…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100671] Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x o…
Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig sandbox that allowlists get_cookie(), which returns any cookie sent with the current request, including the visitor's session cookie. Because the read oc…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100622] capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from…
capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100568] OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, al…
OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agent callers to read and execute ownerless command jobs. Attackers can inspect stored environment variables and force-run disabled or unscheduled command jobs to access secrets and execute operator-authored commands.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100543] OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the…
OpenClaw (npm package openclaw) before 2026.8.1 could include deterministic hashes computed over the original, unredacted configuration in redacted configuration responses. When the Gateway password had low entropy and the remaining configuration values were reconstructable, these hashes acted as offline password verifiers: a caller able to obtain the redacted configuration (for example via config…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-52622] An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES…
An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function
M Alto vulnerabilidad
24/09/2026
[CVE-2026-63645] OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /co…
OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filter. The filter does not recognize dsn or creds field names, so meta_postgres_dsn, meta_postgres_ro_dsn, meta_ddl_dsn, and usage_reporting_creds can be re…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-61782] Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the d…
Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/key` endpoint with no authentication and wildcard CORS (`Access-Control-Allow-Origin: *`). Any network-adjacent or remote attacker can send a single unauth…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-94611] authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik …
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-51995] An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive inf…
An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components
M Alto vulnerabilidad
23/09/2026
[CVE-2026-80423] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain se…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86064] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-o…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/api/logs/logSender.go and applied process-wide through Profile.Apply, allowing a remote client to ch…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76089] Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-no…
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks. Any authenticated user able to invoke the action can enumerate notification IDs an…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-76712] A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized ac…
A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security co…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77246] MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits attacker-controlled Atlassian service headers, including X-Atlassian-Confluence-Url, to select a public attacker hostname or one allowed by MCP_ALLOWED_URL_DOMAINS…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-86059] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organizatio…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucket.one because those protected procedures return full provider rows without applying getAccessibleGitProviderIds or an organization check. The application.one route…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-84990] ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/…
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any authenticated non-admin user to list and download system-configuration backups without an administrator check. The download path reaches backup_config.export_backup…
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de exposición de datos en plugin YS LeadGen para WordPress (CVE-2026-1255)
El plugin YS LeadGen para WordPress en versiones hasta 2.1.4 expone datos sensibles de formularios a usuarios no autenticados a través de la acción AJAX 'ysleadgen_get_captured_data'. Atacantes pueden acceder a información personal (nombres, correos, teléfonos) recopilada en formularios de contacto y generación de leads, afectando sitios web corporativos y de marketing en LATAM. El score CVSS 7.5 indica riesgo alto para empresas que dependen de este plugin.