Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-4129] There is an improper access control vulnerability in NI SystemLink that may allow an authenticated u…
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-4130] There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulner…
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88924] A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownersh…
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an ar…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84821] Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.
Unauthenticated Broken Access Control in WP Fast Total Search
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84816] Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WPCS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84819] Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WPAdverts
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81796] Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Unauthenticated Broken Authentication in WP Travel

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81799] Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 version…
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81800] Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés)
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81801] Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Subscriber Settings Change in WP-Stateless
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81803] Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Subscriber Remote Code Execution (RCE) in RepairBuddy
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81804] Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versi…
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81805] Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Unauthenticated Privilege Escalation in SiteSkite
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81794] Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81795] Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81786] Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions…
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81789] Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6…
Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81783] Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Subscriber Broken Authentication in MailMunch – Grow your Email List
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81784] Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
Unauthenticated PHP Object Injection in Wise Chat
M Alto vulnerabilidad
10/09/2026
[CVE-2026-46387] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A crafted HTTP/2 DATA payload using a high compression ratio, such as gzip, deflate, or brotli compressed data, could cause Su…