Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-97063] X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated end…
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as victims via POST /sys/emailOrMobileLogin/login to hijack accounts.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-97064] X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled…
X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92161] FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other pro…
FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTrustedEmail(). When Discord sign-in is enabled, an unauthenticated attacker who knows the email addre…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-62262] Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earl…
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the unvalidated value in the search rules, and include/functions_search.inc.php integer-cas…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-39353] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the directory is automatically trusted by Mdl_templates and can be selected as publi…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-42322] Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/…
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructing the stored filename. An authenticated administrator can upload image content with a server-executable final extension, causing the file to be placed…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93641] An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z…
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93642] An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z…
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93643] When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an …
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93647] An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. …
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-100075] In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ct…
In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA contexts but leaves stale n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending()…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92609] Session fixation in HTTP management authentication allows remote attackers to gain unauthorized acce…
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Crítico vulnerabilidad
25/09/2026
Vulnerabilidad crítica en plugin Bookly para WordPress permite acceso no autorizado a datos de reservas
El plugin Bookly para WordPress (versiones hasta 28.2) contiene una vulnerabilidad de Referencia Directa a Objetos (IDOR) en acciones AJAX que permite a atacantes acceder y manipular datos de reservas, sesiones y órdenes sin autenticación. Afecta directamente a negocios de servicios en LATAM que usan este plugin para gestionar citas y pagos online, exponiendo información de clientes y transacciones.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-89055] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in a…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product …
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-14281] The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo…
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/` and the absence of a key allowlist in the `finish_registration_logic` function, which…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92288] Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow u…
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method de…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-95699] Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users acce…
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93291] Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-m…
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-13249] An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web manageme…
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updati…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-61741] http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies…
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, a…