Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 5251 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90647] ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper ce…
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90616] In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to fi…
In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90556] Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing save…
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-90558] sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting rout…
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90559] snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(Byte…
snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90560] zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDict…
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90553] vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor l…
vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/09/2026
[CVE-2026-90537] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid dail…
M Alto vulnerabilidad
12/09/2026
[CVE-2026-15451] The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in ver…
The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-lev…
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica de ejecución remota de código en The Events Calendar para WordPress hasta versión 6.17.4
The Events Calendar plugin para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones hasta 6.17.4. La falla reside en la función is_safe_widget_instance que puede ser eludida mediante métodos mágicos de PHP durante el pre-parseo, permitiendo a atacantes no autenticados ejecutar código arbitrario. Empresas en LATAM que operan sitios WordPress con este plugin están expuestas a compromisos críticos de integridad y disponibilidad.
M Crítico vulnerabilidad
12/09/2026
RCE crítica en The Events Calendar para WordPress hasta v6.17.3
The Events Calendar plugin para WordPress es vulnerable a Ejecución Remota de Código (RCE) en todas las versiones hasta 6.17.3. La vulnerabilidad existe en la función parse_array() debido a validación insuficiente del mapa 'classes' del widget, permitiendo que payloads de arrays simples eluda el control is_safe_widget_instance() y alcance el punto de invocación de funciones. Afecta directamente a sitios WordPress en México y LATAM que utilizan este plugin popular para gestión de eventos.
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inyección de objetos PHP en plugin Tutor LMS para WordPress
El plugin Tutor LMS (versiones ≤4.0.7) contiene una vulnerabilidad de inyección de objetos PHP en el manejador AJAX `tutor_save_withdraw_account` que permite a atacantes no autenticados ejecutar código mediante el parámetro `withdraw_method_field`. Afecta principalmente a plataformas de educación en línea y cursos corporativos en LATAM que dependen de este plugin en WordPress. El riesgo es alta (CVSS 8.8) al carecer de validación de capacidades/roles, confiando solo en nonce.
M Alto vulnerabilidad
12/09/2026
Vulnerabilidad alta de inclusión de archivos locales en plugin GEO my WP para WordPress
El plugin GEO my WP en todas las versiones hasta 4.5.5.3 es vulnerable a Local File Inclusion (LFI) a través de la función gmw_posts_locator_ajax_info_window_loader. Atacantes sin autenticación pueden incluir y ejecutar archivos PHP arbitrarios en el servidor, comprometiendo la integridad del sitio y permitiendo ejecución de código malicioso. Esta vulnerabilidad afecta significativamente a sitios inmobiliarios, directorios y plataformas de ubicación operadas en LATAM.
M Alto vulnerabilidad
12/09/2026
Inyección SQL en plugin rtMedia para WordPress afecta versiones hasta 4.7.11
El plugin rtMedia para WordPress, BuddyPress y bbPress es vulnerable a inyección SQL ciega basada en tiempo a través del parámetro 'compare' en todas las versiones hasta la 4.7.11. Atacantes no autenticados pueden ejecutar consultas SQL adicionales explotando insuficiente validación de entrada. Esta vulnerabilidad afecta especialmente a sitios de medios, redes sociales corporativas y comunidades en línea operadas por empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-84099] The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a …
The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-84171] The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of u…
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
M Crítico vulnerabilidad
12/09/2026
[CVE-2026-85681] The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one …
The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled …
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87759] The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check…
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87842] The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check be…
The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
M Alto vulnerabilidad
12/09/2026
[CVE-2026-87888] The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST rout…
The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing WordPress plugin before 3.5.7's settings page.