Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
26/09/2026
[CVE-2026-77203] The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalati…
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.6.0. This is due to the groups_join() function deriving group-join eligibility from the ambient post's author capabilities via the global $post->post_author rather than from the currently authenticated user's own capabilities, while simultaneously minting a…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100686] Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/group…
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in other workspaces by modifying user group role mappings.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100615] Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowin…
Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover its plaintext credential. Attackers with apikey_manager role can enumerate same-owner API keys, rotate a stronger sibling through the PUT endpoint, and obtain the replacement plaintext secret to authenticate as…
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw Codex permite ejecución remota de código sin autorización
OpenClaw Codex anterior a versión 2026.7.1 presenta falla en validación de autorización que permite a usuarios no propietarios con acceso a comandos crear enlaces nativos y ejecutar operaciones con acceso a archivos, herramientas y procesos del sistema. Afecta principalmente a empresas que utilizan esta plataforma para orquestación de infraestructura en entornos cloud de LATAM.
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw (npm) permite escalación de privilegios en Gateway
OpenClaw versiones anteriores a 2026.7.1 expone herramientas administrativas restringidas (gateway y cron) a través del endpoint chat.send, permitiendo que usuarios sin permisos de propietario ejecuten operaciones privilegiadas en despliegues con autenticación. Afecta principalmente a infraestructuras en nube que utilizan este paquete npm en sistemas de orquestación y automatización.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-79153] Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in …
Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems.
M Alto vulnerabilidad
25/09/2026
Escalación de privilegios alta en plugin Optima Express IDX para WordPress hasta v8.7.5
El plugin Optima Express IDX para WordPress contiene una vulnerabilidad de escalación de privilegios (CVSS 7.3) que permite a atacantes no autenticados ejecutar funciones administrativas a través de la acción AJAX `wp_ajax_nopriv_ihf_clear_cache`. La vulnerabilidad afecta todas las versiones hasta la 8.7.5 y expone sitios inmobiliarios y portales empresariales en México y LATAM que utilizan este plugin. Un atacante podría comprometer credenciales de autenticación y obtener acceso administrativo completo.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad alta de escalada de privilegios en plugin Knit Pay para WordPress (CVE-2026-89426)
El plugin Knit Pay para WordPress, utilizado para procesar pagos con Cashfree, Instamojo, Razorpay y PayPal, contiene una vulnerabilidad de escalada de privilegios (CVSS 8.8) en versiones hasta 9.6.1.0. La falla permite a atacantes modificar roles de usuario a través de campos de entrada de Gravity Forms, comprometiendo el acceso administrativo. Afecta directamente a tiendas en línea, plataformas de suscripción y negocios digitales en LATAM que dependen de estos gateways de pago.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-14281] The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo…
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/` and the absence of a key allowlist in the `finish_registration_logic` function, which…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-94609] authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account…
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from …
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Paytium para WordPress
El plugin 'Paytium: Mollie payment forms & donations' para WordPress contiene una vulnerabilidad de escalada de privilegios (CVSS 9.8) en versiones hasta 5.0.3 que permite a atacantes eludir mecanismos de validación de firmas y obtener privilegios administrativos. Afecta directamente a tiendas de e-commerce, plataformas de donaciones y sistemas de pago integrados con Mollie en México y Latinoamérica.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17645] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated atta…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17472] IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unau…
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-76713] A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (AL…
A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-83597] Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent…
Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair can interact with or hijack those visible process windows to execute arbitrary commands with SYSTEM privileges. This issue …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-83598] Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Ag…
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulner…
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de escalada de privilegios en CUPS y cups-filters
Se identificó una vulnerabilidad de escalada de privilegios (CVSS 8.2) en CUPS cuando se utiliza con el backend serial de cups-filters. Un usuario local miembro del grupo lpadmin puede configurar una impresora con backend serial privilegiado para escribir datos arbitrarios en cualquier archivo del sistema con permisos de root. Esta falla afecta especialmente a infraestructuras de impresión compartida en empresas medianas y grandes en México y Latinoamérica.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-12470] The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unau…
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrar…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-13355] The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in vers…
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94425] A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is t…
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.