Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
887
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82455] RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extrac…
RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can instead be written outside of it, breaking the extraction safety boundary. The fix resolves the real path of the parent…
M Crítico vulnerabilidad
Hace 4 días
Vulnerabilidad crítica en argocd-mcp 0.8.0: exposición de interfaz HTTP sin autenticación
ArgoCD MCP versión 0.8.0 expone su transporte HTTP en todas las interfaces de red sin requerir credenciales cuando ARGOCD_API_TOKEN está configurado. Atacantes con acceso a la red pueden invocar la superficie completa de herramientas utilizando el token del operador para crear aplicaciones, ejecutar sincronizaciones y modificar recursos de Argo CD. Esta vulnerabilidad afecta crítica a infraestructuras de CI/CD en empresas que operan Kubernetes en LATAM.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82457] su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before a…
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncate to root's identifier, causing su-exec to execute target programs with root privileges instead of intended unprivileged accounts.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82450] BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import f…
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename in the ZIP archive, which is stored in the public web root and executed by unaut…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82447] Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompt…
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-82448] Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that al…
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.
M Crítico vulnerabilidad
Hace 4 días
Ejecución Remota de Código en Plugin Sigma Forms Pro para WordPress (CVE-2026-14494)
El plugin Sigma Forms Pro para WordPress (versiones hasta 1.4.5) es vulnerable a ejecución remota de código (RCE) mediante la función handle_form_submission. La vulnerabilidad permite a atacantes no autenticados subir archivos maliciosos al explotar la asignación dinámica de capacidades unfiltered_upload y el bypass de validación de tipos MIME. Afecta directamente a sitios WordPress en LATAM que utilizan este plugin para gestión de formularios sin parches.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-77012] The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its…
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied conten…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76586] The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does no…
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-77007] The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perfo…
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to the connected BigBlueButton server.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76548] The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end fil…
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16600] The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJ…
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting in a full-read Server-Side Request Forgery.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-16947] The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a …
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success respon…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16061] The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from th…
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta de intercepción de tráfico en BOSH Director vCenter CPI (CVE-2026-41012)
Una vulnerabilidad de intercepción de tráfico en BOSH Director vCenter CPI permite a atacantes posicionados entre el Director y vCenter suplantar la API REST de vCenter y capturar credenciales de administrador mediante autenticación HTTP Basic. Un atacante con capacidad de interceptar tráfico puede comprometer completamente la infraestructura de virtualización. En LATAM, esto afecta altas centros de datos y plataformas de IaaS que dependen de vCenter para gestión de máquinas virtuales.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en MapFish Print permite inyección XXE en servidores de mapas
MapFish Print versiones anteriores a 3.28.30, 3.30.32, 3.31.24, 3.33.16 y 4.0.5 contienen una vulnerabilidad de inyección XML External Entity (XXE) en el endpoint /api/print3/print. Un atacante remoto puede enviar capas GML maliciosas para ejecutar ataques XXE sin validación de entidades externas, poniendo en riesgo servidores de cartografía y sistemas SIG en gobiernos, empresas constructoras y plataformas de infraestructura en LATAM.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en free5GC 1.4.4 permite acceso no autorizado a contexto de autenticación
free5GC, implementación de código abierto del núcleo 5G, presenta una vulnerabilidad en el componente AUSF (Authentication Server Function) en versiones 1.4.4 y anteriores. El almacenamiento inseguro de estado de autenticación por suscriptor en una estructura global permite que atacantes accedan o manipulen credenciales de usuarios. Esta vulnerabilidad afecta directamente a operadores de telecomunicaciones y proveedores de infraestructura 5G en LATAM que ejecuten free5GC en entornos de producción.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en Graylog Server y Forwarder permite manipulación de logs (CVE-2026-55841)
Una vulnerabilidad en el parser de syslog FortiGate de Graylog Server (versiones anteriores a 6.3.12, 7.0.7 y 7.1.2) y Graylog Forwarder (anterior a 7.3) permite a atacantes manipular campos de log mediante texto especialmente crafteado dentro de valores entrecomillados. Esto afecta a empresas en LATAM que utilizan Graylog para centralizar y auditar logs de seguridad, comprometiendo la integridad de registros altas para forensia y cumplimiento normativo.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad DoS en multer permite bloqueo de event loop en Node.js
multer, middleware popular para procesar multipart/form-data en Node.js, es vulnerable a ataques de denegación de servicio (DoS). Un atacante puede enviar solicitudes HTTP especialmente diseñadas con nombres de campo malformados que fuerzan al parser a iterar arreglos sparse de tamaño máximo, bloqueando el event loop e impidiendo que la aplicación procese otras peticiones. Afecta aplicaciones web en producción que usen multer para carga de archivos, especialmente relevante en empresas LATAM con infraestructura Node.js alta.