Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
27/07/2026
[CVE-2026-64533] In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow …
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conversion log_replay() converts DIR_PAGE_ENTRY_32 records into DIR_PAGE_ENTRY records when replaying version 0 restart tables. During this conversion, the memmove() length is derived directly from the on-disk lcns_follow field: memmove(&dp->vcn, &dp0->vcn_low, 2 * sizeof(u64) + …
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-64534] In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED be…
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvmet_req_uninit() is called unconditionally. However, if the command arrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init() had returned false and percpu_ref_tryget_liv…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-64535] In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF wh…
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection and a digest mismatch occurs on a non-final H2C_DATA PDU during an R2T-based data transfer, the digest error handler in nvmet_tcp_try_recv_ddgst() calls nvmet_req_uninit() — which p…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-64536] In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB rea…
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop The loop in is_ap_in_tkip() iterates over IEs without verifying that enough bytes remain before dereferencing the IE header or its payload: - pIE->element_id and pIE->length are read without checking that i + sizeof(*pIE)
M Alto vulnerabilidad
27/07/2026
[CVE-2026-14837] Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH …
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism. A low-privileged local attacker can bypass verification of the SSH enable file signature and enable SSH access on the device. Successful exploitation may result in unauthorized administrative access and complete system compromise.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-9830] The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its…
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13597] The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its …
The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13714] The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate th…
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it possible for unauthenticated attackers to upload arbitrary PHP files and achieve rem…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-13726] The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it…
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-14235] The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to th…
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected package file without authorization.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-14289] The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one…
The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request handlers, whose only protection is derived from a cryptographic key that is empty in the default, unconfigured state, allowing unauthenticated attackers to write an arbitrary file into a web-accessible directory and achieve remote code execution.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-12255] The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site…
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-12394] The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end reg…
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-12493] The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify …
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained f…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-13152] The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent …
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13332] The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unaut…
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.
M Alto vulnerabilidad
27/07/2026
[CVE-2025-15662] The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not r…
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing database credentials and secret keys) and to make server-side requests to internal r…
M Alto vulnerabilidad
26/07/2026
[CVE-2026-57989] Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo…
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
26/07/2026
[CVE-2026-57990] Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an una…
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
26/07/2026
[CVE-2026-17496] NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injec…
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to inc…