Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 min
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1740
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-62777] Missing authentication for critical function in Windows License Manager allows an authorized attacke…
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61367] Missing authentication for critical function in Windows Remote Desktop Services allows an authorized…
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61364] Missing authentication for critical function in Windows Remote Desktop Services allows an authorized…
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61365] Missing authentication for critical function in Windows Remote Desktop Services allows an authorized…
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61356] Missing authentication for critical function in Windows Remote Desktop Services allows an authorized…
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-42976] Missing authentication for critical function in Windows RPC API allows an authorized attacker to ele…
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72920] SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAcc…
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed i…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72748] AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json…
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achiev…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-58115] A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions <…
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attac…
M Alto vulnerabilidad
11/08/2026
Vulnerabilidad de autenticación ausente en Swing Music 3.0.0 permite creación de cuentas no autorizadas
Swing Music 3.0.0 contiene una vulnerabilidad alta (CVSS 7.5) que permite a atacantes no autenticados crear cuentas de usuario arbitrarias mediante el endpoint POST /auth/profile/create, que está exento de verificación JWT. Un atacante puede registrar una cuenta y acceder a funcionalidades protegidas del servidor, comprometiendo datos y servicios en infraestructuras de empresas en México y LATAM que ejecuten esta versión.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72535] A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remo…
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks before creating a customer portal session linked to any tenant Stripe account. An attacker can access and manage subscript…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72536] A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remo…
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. An attacker can create payment intents and alter billing for any tena…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15563] A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without auth…
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18941] A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and t…
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no security manager is installed. This default allows unauthenticated and unauthorized access to feature-server, registry-server, and offline-server endpoints. A remote attacker, by exploiting this missing authentication, could achieve remote code execution (R…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-15581] A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the …
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and directly access the TAS backend API. An attacker can exploit this to read, tamper with, or delete monitoring data and configurations, and inject arbitrary data into the service, potentially disrupting tenant operations.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72871] Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated…
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/github/setup route in apps/dokploy/pages/api/providers/github/setup.ts trusts gh_init organizationId and userId values from the state parameter and calls createGithub in packages/server/src/services/github.ts, allowing an attacker to insert a GitHub App provider containing client_sec…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72688] A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unaut…
A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session check, defeating the only access control protecting stored contract files.
M Crítico vulnerabilidad
10/08/2026
Vulnerabilidad crítica de autenticación en phpfm 1.8.0 permite acceso no autorizado al sistema de archivos
phpfm versión 1.8.0 y anteriores contiene una vulnerabilidad de autenticación faltante que permite a atacantes remotos sin credenciales acceder completamente al gestor de archivos del servidor. Los atacantes pueden leer, escribir, eliminar y cargar archivos en cualquier parte del sistema de archivos, comprometiendo la integridad y confidencialidad de datos críticos. Esta vulnerabilidad afecta directamente a empresas en LATAM que utilizan esta herramienta para administración de servidores web.
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad de autenticación faltante en FUXA 1.3.3 expone datos históricos de sensores
FUXA, plataforma de supervisión industrial de código abierto, contiene una vulnerabilidad que permite a atacantes no autenticados acceder a datos históricos completos de sensores mediante el evento Socket.IO DAQ_QUERY. Aunque otros eventos requieren validación de token cuando secureEnabled=true, DAQ_QUERY carece de verificación de autenticación. Esta exposición afecta especialmente a plantas de manufactura, utilities y sistemas SCADA en México y Latinoamérica que utilizan FUXA para monitoreo de dispositivos altas.
M Crítico vulnerabilidad
10/08/2026
Vulnerabilidades críticas en NASA fprime-gds 3.4.3 permiten ejecución remota de código
NASA fprime-gds versiones hasta 3.4.3 contiene múltiples vulnerabilidades que permiten a atacantes no autenticados ejecutar código arbitrario en estaciones terrestres y manipular comandos de naves espaciales. La aplicación Flask carece de autenticación en todos sus endpoints, exponiendo sistemas críticos de agencias espaciales y centros de investigación en LATAM que operen este software.