Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1799
Esta semana
RSS
M Alto vulnerabilidad
17/07/2026
[CVE-2026-63101] Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthe…
Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV export endpoint which lacks any authentication decorator. Attackers can enumerate sequential group IDs via brute-force, tri…
M Alto vulnerabilidad
17/07/2026
[CVE-2026-12691] Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platfor…
Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
M Crítico vulnerabilidad
17/07/2026
[CVE-2026-62241] clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-de…
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known …
M Alto vulnerabilidad
16/07/2026
[CVE-2024-34268] EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was …
EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-63087] Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote a…
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbi…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-57206] SimpleChat is a secure AI conversation application with personal and group workspaces for document-g…
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/`, `POST /api/admin/plugins/repair/`, and `POST /…
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-45695] Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, c…
Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to /api/v1/repo/exists and forwards attacker-supplied SFTP storage configuration to blob.NewStorage, where externalSSH: true an…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/07/2026
[CVE-2026-46339] 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware d…
9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.
M Alto vulnerabilidad
15/07/2026
[CVE-2026-58658] GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure …
GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker configuration by exploiting unprotected /serveLogs and /debug endpoints on the worker port. Attackers can enumerate model instance IDs to stream serving logs containing prompts and completions, c…
B Crítico vulnerabilidad
15/07/2026
[CVE-2026-53512] Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the lega…
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant authenticates only possession of the bound refreshToken row and matching client_id, without verifying the confidential client's client_secret, allowing an attacker with a valid refresh_token to mint access tokens …
A Crítico vulnerabilidad
14/07/2026
[CVE-2026-48325] ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could re…
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-24229] NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, …
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
A Alto vulnerabilidad
14/07/2026
[CVE-2026-48252] Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability…
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50451] Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) all…
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50444] Missing authentication for critical function in Windows Server Update Service allows an authorized a…
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-57969] Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to el…
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50333] Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker …
Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-62422] In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.14843…
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
A Crítico vulnerabilidad
14/07/2026
[CVE-2026-58319] Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication.…
Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster integrity and availability and leading to cluster instability or denial of service. This issue affects Apache Doris versions prior to 3.1.0. U…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15416] A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could all…
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.