Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-16038] The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway …
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin TrueBooker para WordPress
El plugin TrueBooker – Appointment Booking and Scheduler System para WordPress contiene una falla de autorización que permite a atacantes no autenticados cambiar contraseñas de cuentas administrativas en versiones hasta la 1.2.3. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan WordPress para gestión de citas y reservas, exponiendo el control total de sus sitios web.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de escalada de privilegios en Microsoft Teams (CVE-2026-65667)
Microsoft Teams presenta una falla de autorización que permite a atacantes no autorizados escalar privilegios sobre la red con puntuación CVSS 10.0. Esta vulnerabilidad afecta directamente a organizaciones en México y Latinoamérica que dependen de Teams para comunicaciones empresariales y colaboración. El impacto potencial incluye acceso no autorizado a datos sensibles, comunicaciones y recursos compartidos dentro del ecosistema corporativo.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62830] Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a …
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70636] Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated at…
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-67621] Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated works…
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, con…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48085] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional GLOBAL_ADMIN accounts without verifying that an admin already exists. Any unauthenticated network attacker who can submit a same-or…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48088] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication. The handler logs an "Unauthorized crypto key storage attempt" warning when neither …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18277] Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 2…
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66712] Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
Unauthenticated Broken Access Control in Simple Membership
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66708] Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Unauthenticated Broken Access Control in Total Upkeep
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66470] Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Subscriber Broken Access Control in Frontend Admin by DynamiApps
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65554] Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65541] Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Unauthenticated Broken Access Control in Staff Training
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65504] Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28140] Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Unauthenticated Broken Access Control in JetFormBuilder
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-28005] Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65551] Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Ac…
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad de autorización faltante en TinyAGI 0.0.20 permite acceso remoto no autorizado
Se ha detectado una vulnerabilidad de seguridad en TinyAGI versión 0.0.20 que afecta la función processMessage del componente Message API Endpoint. La falla permite eludir controles de autorización y ejecutar acciones remotas sin validación de permisos. El exploit ha sido divulgado públicamente, aumentando el riesgo de explotación inmediata en entornos de producción en Latinoamérica que utilicen esta versión.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-16734] The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the call…
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to change the amount of a payment intent that the Stripe Payment Forms by WP Full Pay …