Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-53451] Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and…
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or parent-directory traversal an…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76224] ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulne…
ArcadeDB before 26.8.1 (arcadedb-gremlin, affected
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-43961] A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio…
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-18937] The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accep…
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a classic (non-block) is active.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-75911] CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter f…
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml file to a repository. When a user clones and opens the repository in CodeWhale, the AI model gains access to exec_shell and task_shell tools, enabling execution o…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-75858] CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code…
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python code to run in a python3 interpreter without consulting the user's configured --approval-policy and w…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-45117] MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not…
MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is available. install/index.php processes the values with addcslashes(), but the $characters argument added in MyBB 1.8.13 does…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73343] Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-50187] Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the d…
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-32444] Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Contributor Remote Code Execution (RCE) in Cwicly
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-75827] Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare…
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function through a data directive to append PHP payloads to web-accessible files, achieving remote code execution.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-34789] FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/Prope…
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd document, which executes module-level Python code, and the legacy pickle branch also imp…
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-19478] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19980] A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE930…
A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated re…
M Alto vulnerabilidad
16/08/2026
Inyección de código en plugin WCPOS para WooCommerce afecta tiendas en línea
El plugin WCPOS (Point of Sale) para WooCommerce en WordPress contiene una vulnerabilidad alta de inyección de código en el motor de plantillas 'thermal' hasta la versión 1.9.14. Atacantes autenticados pueden ejecutar código PHP arbitrario a través del renderizador de recibos, comprometiendo datos de ventas y clientes en tiendas electrónicas de México y Latinoamérica que utilizan este sistema POS.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-73678] MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution …
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-73679] ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module th…
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before passing it to eval() in the renderWithPhp() method, bypassing HTML Purifier saniti…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-46439] compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 a…
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads i…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19768] Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow…
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
M Alto vulnerabilidad
14/08/2026
Vulnerabilidad alta de ejecución remota de código en Grav CMS 2.0.12 y anteriores
Grav CMS versiones anteriores a 2.0.13 contiene una vulnerabilidad de ejecución remota de código (RCE) en la validación de configuración del plugin Flex Objects. Un atacante autenticado puede eludir la validación de nombres mediante notación de arreglos y cargar un archivo ZIP malicioso con código PHP, escribiendo archivos ejecutables en el directorio raíz web. Esta vulnerabilidad afecta directamente a portales, sitios dinámicos y plataformas de gestión de contenidos en organizaciones de México y Latinoamérica que utilizan esta CMS.