Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 min
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105213] ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentica…
ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta de autenticación en Ahsay AhsayCBS afecta versiones hasta 10.3.2
Se detectó una vulnerabilidad en Ahsay AhsayCBS (versiones ≤10.3.2) que compromete la función de autenticación checkSysPwd mediante manipulación del parámetro random en la API. El ataque es remoto y el exploit está públicamente disponible. Afecta principalmente a empresas en LATAM que usan este software de backup en cloud híbrido, exponiendo acceso no autorizado a sistemas de respaldo altas.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-91078] The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the…
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-103514] The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it…
The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an account's password and has observed a valid code within its validity window to replay it and bypass two-factor authentication, including on administrator accounts.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-97637] The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Coo…
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-19660] The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up t…
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled …
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-14378] The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator …
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the privileged identity: `verify_nonce_and_capability()` incorrectly checks the `manage_options` capability on the user identified by …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
01/10/2026
Vulnerabilidad crítica de autenticación en Fleet versiones anteriores a 4.87.0
Fleet antes de la versión 4.87.0 contiene una vulnerabilidad de omisión de autenticación en la API de dispositivos que permite a atacantes no autenticados usar nombres de host o números de serie como tokens válidos. Los atacantes pueden acceder a datos de dispositivos iOS/iPadOS, instalar software malicioso e iniciar migraciones MDM. Esta vulnerabilidad afecta empresas en LATAM que gestionan flotas de dispositivos móviles corporativos.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-75957] The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable…
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `check…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103536] A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the …
A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102128] An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act o…
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102106] Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administr…
Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-88920] An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote…
An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102248] A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of t…
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102245] A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknow…
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101280] A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the functi…
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101281] A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerabilit…
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c75…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101077] A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the…
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101073] A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of…
A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa of the component CGI Dispatcher. Performing a manipulation results in improper authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in…
M Crítico vulnerabilidad
27/09/2026
[CVE-2026-100886] A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. …
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any wa…