Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14168] A low privileged remote attacker can gain administrator privileges due to missing authorization at t…
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14924] The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability,…
The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66473] Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-64746] An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and i…
An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.
J Alto vulnerabilidad
27/07/2026
[CVE-2026-65922] An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with li…
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository access to write to restricted internal metadata areas under specific conditions. Successful abuse is limited to integrity and availability impact at a low level; confidentiality is not affected.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59535] Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Unauthenticated Broken Access Control in Thrive Product Manager
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59536] Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Unauthenticated Broken Access Control in CoCart – Headless ecommerce

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59529] Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59530] Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59534] Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Unauthenticated Broken Access Control in Post My CF7 Form
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59690] A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Objec…
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.
M Crítico vulnerabilidad
25/07/2026
[CVE-2026-66012] SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint…
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publis…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66027] Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that all…
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's sess…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-10033] The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions u…
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities and the upload_files capability to any non-administrator WordPress role or user,…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-58275] Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a netw…
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-47724] nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to v…
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API trusts the bearer token for authorisation; per-CA ownership is enforced only in the Web layer." The Web UI gates state-c…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65916] CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in…
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65895] Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin con…
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials en…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65500] Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPres…
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65495] Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Unauthenticated Broken Access Control in Dokan Pro