Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
25/09/2026
[CVE-2026-79153] Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in …
Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems.
M Alto vulnerabilidad
25/09/2026
Escalación de privilegios alta en plugin Optima Express IDX para WordPress hasta v8.7.5
El plugin Optima Express IDX para WordPress contiene una vulnerabilidad de escalación de privilegios (CVSS 7.3) que permite a atacantes no autenticados ejecutar funciones administrativas a través de la acción AJAX `wp_ajax_nopriv_ihf_clear_cache`. La vulnerabilidad afecta todas las versiones hasta la 8.7.5 y expone sitios inmobiliarios y portales empresariales en México y LATAM que utilizan este plugin. Un atacante podría comprometer credenciales de autenticación y obtener acceso administrativo completo.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad alta de escalada de privilegios en plugin Knit Pay para WordPress (CVE-2026-89426)
El plugin Knit Pay para WordPress, utilizado para procesar pagos con Cashfree, Instamojo, Razorpay y PayPal, contiene una vulnerabilidad de escalada de privilegios (CVSS 8.8) en versiones hasta 9.6.1.0. La falla permite a atacantes modificar roles de usuario a través de campos de entrada de Gravity Forms, comprometiendo el acceso administrativo. Afecta directamente a tiendas en línea, plataformas de suscripción y negocios digitales en LATAM que dependen de estos gateways de pago.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-14281] The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo…
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/` and the absence of a key allowlist in the `finish_registration_logic` function, which…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-94609] authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account…
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing role to a group without holding the permissions that gate those privileges. Group hierarchy checks do not consistently account for superuser status inherited from …
M Crítico vulnerabilidad
24/09/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Paytium para WordPress
El plugin 'Paytium: Mollie payment forms & donations' para WordPress contiene una vulnerabilidad de escalada de privilegios (CVSS 9.8) en versiones hasta 5.0.3 que permite a atacantes eludir mecanismos de validación de firmas y obtener privilegios administrativos. Afecta directamente a tiendas de e-commerce, plataformas de donaciones y sistemas de pago integrados con Mollie en México y Latinoamérica.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17645] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated atta…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17472] IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unau…
IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources due to the use of wildcards in RBAC permission definitions.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-76713] A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (AL…
A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file system with root privileges, potentially resulting in full system compromise.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-83597] Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent…
Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair can interact with or hijack those visible process windows to execute arbitrary commands with SYSTEM privileges. This issue …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-83598] Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Ag…
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulner…
M Alto vulnerabilidad
22/09/2026
Vulnerabilidad alta de escalada de privilegios en CUPS y cups-filters
Se identificó una vulnerabilidad de escalada de privilegios (CVSS 8.2) en CUPS cuando se utiliza con el backend serial de cups-filters. Un usuario local miembro del grupo lpadmin puede configurar una impresora con backend serial privilegiado para escribir datos arbitrarios en cualquier archivo del sistema con permisos de root. Esta falla afecta especialmente a infraestructuras de impresión compartida en empresas medianas y grandes en México y Latinoamérica.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-12470] The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unau…
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'cmp_ajax_import_settings' AJAX action in all versions up to, and including, 4.1.17. This makes it possible for authenticated attackers, with Editor-level access and above, to update arbitrar…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-13355] The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in vers…
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET parameter 'rwmb_frontend_field_object_id' without any authorization check, and Form::p…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94425] A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is t…
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/09/2026
[CVE-2026-48826] HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend…
HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through the X-Tenant request header. Because every self-registered user who creates a grou…
M Alto vulnerabilidad
21/09/2026
[CVE-2025-71421] UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the ed…
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92540] The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce t…
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-92541] The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote…
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-82842] The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for …
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administ…