Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-86520] Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time da…
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-54767] WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controlle…
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafis…
M Alto vulnerabilidad
17/09/2026
Vulnerabilidad de credenciales hardcodeadas en Dell OpenManage Server Administrator anterior a 11.1.0.3
Dell OpenManage Server Administrator en versiones anteriores a 11.1.0.3 contiene credenciales hardcodeadas que permiten acceso no autenticado remoto. Un atacante podría obtener acceso no autorizado a la consola de administración de servidores, comprometiendo la infraestructura alta. Afecta especialmente a centros de datos y empresas con servidores Dell en LATAM que utilicen esta herramienta sin actualizar.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92787] Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowin…
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-66890] The affected products use hard-coded credentials, which could allow remote access to files with root…
The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-68950] The affected products use hard-coded credentials, which could allow an attacker to run the ftpd serv…
The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-16141] OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated…
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcR…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-57147] Vulnerabilidad crítica de autenticación en PraisonAI permite falsificación de tokens JWT
PraisonAI versiones anteriores a 0.1.6 contienen una vulnerabilidad de autenticación crítica (CVSS 9.8) donde la clave JWT_SECRET se asigna a un valor público conocido cuando las variables de entorno no están configuradas correctamente. Un atacante remoto no autenticado puede falsificar tokens JWT con identidades arbitrarias, comprometiendo sistemas multi-agente en producción. Afecta especialmente a empresas LATAM que implementan PraisonAI sin sobrescribir explícitamente las credenciales de desarrollo.
M Crítico vulnerabilidad
15/09/2026
Vulnerabilidad crítica en PraisonAI permite falsificación de tokens JWT sin autenticación
PraisonAI versiones anteriores a 0.1.6 utiliza una clave HS256 predeterminada y pública cuando las variables de entorno no están configuradas, permitiendo que atacantes sin autenticación firmen tokens JWT arbitrarios. Esta falla afecta a sistemas que ejecuten plataformas de agentes multiequipo en configuraciones de desarrollo accidentalmente expuestas en producción, comprometiendo completamente el control de acceso.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90509] A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the fun…
A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early thr…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-75940] A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Ch…
A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-81640] An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weake…
An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This weakens or eliminates the security value of the access-point password and may expose the live video stream, device services, status interfaces, and firmware-update functionality.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79740] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79950] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79738] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86673] A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca5…
A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This prod…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80134] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad de credenciales codificadas en SourceCodester Syllabus-Aligned LMS 1.0
Se ha identificado una falla de seguridad alta en SourceCodester Syllabus-Aligned Learning Management & Examination System versión 1.0 que expone credenciales codificadas en el archivo db.php. La vulnerabilidad permite acceso remoto sin autenticación y exploits públicos ya están disponibles. Instituciones educativas y organizaciones en LATAM que utilicen este sistema están en riesgo inmediato de comprometer datos académicos y administrativos.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85148] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85146] SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Un…
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.