Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88016] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88017] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the server-wide userPass map[string]string instead of binding the credential or VFS to the authenticated session. If two accepted credentials use the same username but r…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88018] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81467] Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elem…
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81468] Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elem…
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81046] Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability…
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81048] Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elemen…
Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-79987] A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission ca…
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-4129] There is an improper access control vulnerability in NI SystemLink that may allow an authenticated u…
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-4130] There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulner…
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88924] A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownersh…
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an ar…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84821] Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Unauthenticated Broken Access Control in WP Fast Total Search
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84816] Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WPCS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84819] Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WPAdverts
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81796] Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Unauthenticated Broken Authentication in WP Travel

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81799] Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 version…
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81800] Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés)
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81801] Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Subscriber Settings Change in WP-Stateless
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81803] Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Subscriber Remote Code Execution (RCE) in RepairBuddy
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81804] Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versi…
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration