Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-18452] DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauth…
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-52539] Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environmen…
Outstatic CMS
M Alto vulnerabilidad
28/07/2026
[CVE-2026-13463] IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the…
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.
M Alto vulnerabilidad
27/07/2026
[CVE-2021-32085] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with …
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for o…
M Alto vulnerabilidad
27/07/2026
[CVE-2021-32087] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with …
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileg…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-55579] Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before versi…
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password admin (SHA-512 hash stored at pheditor.php:11). There is no mechanism to force a password change on first login. Any deployment using the default credentials grants an attacker full access to the file editor, file upload, and terminal featur…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-65879] Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret …
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-47410] PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior …
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but only fires when `PLATFORM_ENV != "dev"`; the default value of `PLATFORM_ENV` is `"dev"`, so the check …
M Alto vulnerabilidad
20/07/2026
[CVE-2026-47255] AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to versio…
AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw storage SQL; blocking direct storage metadata access through raw SQL; fail-closed ou…
L Crítico vulnerabilidad
17/07/2026
[CVE-2026-13446] IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptog…
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-45336] HireFlow is a web-based interview management system for managing candidates, scheduling interviews, …
HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public source value to forge cookies containing role=admin and user_id values and bypass authentication. The advisory lists ver…
M Crítico vulnerabilidad
15/07/2026
[CVE-2026-49352] 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback…
9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in src/app/api/auth/login/route.js, src/middleware.js, and later src/lib/auth/dashboardSession.js, allowing attackers to forge an auth_token cookie when JWT_SECRET was unset. This issue is fixed in version 0.4.44
M Crítico vulnerabilidad
07/07/2026
[CVE-2026-37270] Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused…
Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.
M Crítico vulnerabilidad
06/07/2026
[CVE-2026-14807] ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenti…
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view application code and obtain the database account and password.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-13768] Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user t…
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
U Crítico vulnerabilidad
01/07/2026
[CVE-2026-7839] UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded defaul…
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, when settings2.txt is absent on first run the repeater writes the literal string "adminadmi2" as the admin password via strcpy_s(saved_password, 64, "adminadmi2"). The HTTP Basic-auth handler wi_decode_auth() checks this password without rate-limiting o…
F Crítico vulnerabilidad
30/06/2026
[CVE-2026-56278] Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('f…
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible in the source code, an attacker can forge valid signed session cookies to imperso…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-50110] Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embed…
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the credentials are stored in an encoded format, the encoding can be reversed to plaintext. The exposed credentials span a broad range of internal services, including database accounts, licensing, replication services, and third-party integrations, meaning succ…
D Alto vulnerabilidad
26/06/2026
[CVE-2026-31928] The DMP-5000 devices are shipped with a default administrative web account with weak authentication …
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides full system access.
M Crítico vulnerabilidad
26/06/2026
[CVE-2026-46386] OpenProject is open-source, web-based project management software. Prior to , the official openproje…
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-deserialization path reachable via the /my/two_factor_devices cookie reader This vulnerability is fix…