Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-74012] Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Editor PHP Object Injection in TaxoPress
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73397] Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Unauthenticated Deserialization of untrusted data in Youzify
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73380] Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73376] Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73366] Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73341] Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Unauthenticated PHP Object Injection in RegistrationMagic
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-66620] Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Editor PHP Object Injection in OptionTree

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-59940] Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap…
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potenti…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-32470] Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-32465] Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
Customer PHP Object Injection in Essential Real Estate
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16138] In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of…
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de inyección de objetos PHP en plugin ARForms para WordPress
El plugin ARForms (Contact Form, Survey, Quiz & Popup Form Builder) para WordPress contiene una vulnerabilidad de inyección de objetos PHP (CVE-2024-13784, CVSS 9.8) en versiones hasta 1.8.5 que permite a atacantes no autenticados inyectar objetos maliciosos mediante deserialización de datos en envíos de formularios. Aunque actualmente no hay cadenas POP conocidas explotadas, esta vulnerabilidad expone sitios web en México y Latinoamérica que utilicen este plugin, afectando formularios de contacto, encuestas y popups que interactúan directamente con usuarios.
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad alta en Podlove Podcast Publisher para WordPress permite eliminación de archivos arbitrarios
El plugin Podlove Podcast Publisher para WordPress (versiones hasta 4.5.3) contiene una vulnerabilidad alta (CVSS 8.8) que permite a atacantes autenticados con acceso de contribuidor eliminar archivos arbitrarios en el servidor. Esta falla en validación de rutas puede derivar en ejecución remota de código, comprometiendo servidores de empresas mediáticas y plataformas de podcasting en LATAM que alojen este plugin.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19826] A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian…
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any fu…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66256] ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. …
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28176] Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Unauthenticated PHP Object Injection in Booking Activities
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28149] Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27380] Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
Editor PHP Object Injection in Car Rental Manager
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73325] Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability tha…
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking Python's pickle machinery during deserialization. Attackers can embed malicious __reduce_…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-67260] Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task…
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the sche…