Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54629] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE VIRTUAL TABLE statements to provide a local path to these modules, which use hashi…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-50006] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards una…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker can select any path writable by the Anyquery server process, cause SQLite to create a database file there, and place attacker-controlled table content in that fi…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-76441] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to…
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en Bifrost permite ejecución remota de código sin autenticación
Bifrost permite registrar clientes MCP a través de su API de gestión sin requerir handshake MCP ni autenticación cuando governance.auth_config.is_enabled=false (configuración por defecto). Un atacante puede ejecutar comandos arbitrarios como el usuario del proceso Bifrost mediante una única solicitud POST /api/mcp/client no autenticada, comprometiendo completamente servidores y gateways en empresas de LATAM que usen esta solución.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90603] A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by thi…
A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90493] A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The …
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81941] IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute …
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81046] Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability…
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88864] Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed th…
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route (supabase/functions/_backend/private/sso/providers.ts) and its controls: the Enterprise plan requirement, SSO provide…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-85545] There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege us…
There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-19436] The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value …
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75998] ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file…
ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81963] Improper link resolution before file access ('link following') in Windows Update Stack allows an aut…
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77487] Improper access control in SQL Server allows an authorized attacker to elevate privileges over a net…
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73028] Improper access control in SQL Server allows an authorized attacker to elevate privileges over a net…
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69282] Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code…
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69273] Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code…
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69268] Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code…
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-26084] A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4…
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86666] A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function …
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not res…