Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64814] In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Developme…
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
M Alto vulnerabilidad
23/07/2026
[CVE-2026-61954] Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Unauthenticated Broken Access Control in PayU India
M Alto vulnerabilidad
23/07/2026
[CVE-2026-59547] Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions…
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce
M Alto vulnerabilidad
23/07/2026
[CVE-2026-61943] Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57367] Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-15015] The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypa…
The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an administrator-bound OAuth Bearer token via a self-registered client, granting full admini…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-12082] The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of…
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13078] A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine uncond…
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB se…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-61267] Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (componen…
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized upd…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60953] Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite…
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator. Successful attacks of this vulnerability can result i…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-47688] FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version…
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power mana…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-47413] PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior …
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`) and forwards the request body's `user_id` and `role` straight into `MemberService.add(wo…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-47416] PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior …
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the route. The handler then calls `MemberService.update_r…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-47412] PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior …
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member of the workspace can issue a single DELETE to wipe the entire workspace, including e…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-47405] PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior …
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to `owner`. The issue is caused by privileged workspace-management routes using the shared dependency `require_workspace_member(...)` without requiring `admin`…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-47409] PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior …
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member can remove any other member, including the workspace owner, using a sin…
S Crítico vulnerabilidad
21/07/2026
[CVE-2026-28309] SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administ…
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
S Crítico vulnerabilidad
21/07/2026
[CVE-2026-28310] SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administr…
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-65007] The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation an…
The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every panel user). This allows any user with admin.login to mint a persistent API key b…
M Alto vulnerabilidad
20/07/2026
[CVE-2026-55544] NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP c…
NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using user-generated Bearer API tokens (`nxtc__...`). The application has an authorization model that restricts normal users to campaigns they created, but multiple MCP campaign handlers ignore the authenticated user ID and que…