Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71944] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71945] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71946] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
[CVE-2026-71947] D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 c…
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.
M Crítico vulnerabilidad
08/08/2026
Plugin AI Copilot – Content Generator para WordPress vulnerable a bypass de autorización
El plugin AI Copilot – Content Generator en WordPress (versiones hasta 1.5.6) presenta una vulnerabilidad crítica de bypass de autorización (CVSS 9.8) que permite a atacantes no autenticados crear cuentas de administrador y comprometer completamente el sitio web. Esta vulnerabilidad afecta especialmente a empresas en LATAM que utilizan WordPress para presencia digital y e-commerce.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en OpenYak permite ejecución de código remoto desde navegadores web
OpenYak, un runtime local para modelos de IA con herramientas integradas, presenta una vulnerabilidad crítica (CVSS 9.6) en versiones anteriores a 1.1.3. El backend del escritorio expone una API HTTP sin validación de origen, autenticación de loopback ni enforcement de Content-Type, con política CORS abierta. Cualquier página web visitada mientras OpenYak se ejecuta puede ejecutar comandos arbitrarios en el sistema local, comprometiendo completamente la máquina del usuario.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de contaminación de prototipos en biblioteca scim-patch anterior a v0.9.1
La biblioteca scim-patch versiones anteriores a 0.9.1 es vulnerable a contaminación de prototipos (prototype pollution) al procesar operaciones SCIM PATCH con valores malformados. Un atacante puede inyectar propiedades en Object.prototype a través de claves como "__proto__.someProp", comprometiendo todos los objetos planos en el proceso Node.js afectado. Esto afecta a servicios que procesan JSON controlado por el atacante, típicamente APIs de identidad y gestión de acceso.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Kata Containers permite ejecución de código en el host
Kata Containers anterior a versión 4.0.0 es vulnerable a ejecución de código en el host mediante anotaciones de configuración sin validar. Un atacante puede especificar una ruta TOML arbitraria a través de la anotación io.katacontainers.config_path para cargar archivos maliciosos del host. Esta vulnerabilidad afecta infraestructuras containerizadas en datacenters y plataformas cloud de empresas LATAM que ejecuten orquestación con Kubernetes.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-61808] LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRA…
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitiga…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-48039] Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to…
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authenticatio…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71851] crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate…
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a cryptographically secure source. This generator was introduced in version 3.1.2-4 and remained present in nearly every 3.x release…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-64637] Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated re…
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-19264] Postiz is an open-source social media scheduling tool. The route that serves locally stored media jo…
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matching and are decoded onl…
M Crítico vulnerabilidad
07/08/2026
[CVE-2022-4995] Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows…
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71558] Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache For…
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to den…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71560] Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory…
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-16258] The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrust…
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-16038] The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway …
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-14205] The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when re…
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de takeover de cuentas en plugin TrueBooker para WordPress (CVE-2026-14364)
El plugin TrueBooker para WordPress (versiones hasta 1.2.3) permite a atacantes no autenticados resetear contraseñas de usuarios arbitrarios mediante validación insuficiente de identidad. Afecta directamente a sitios de servicios (salones, clínicas, agencias) en LATAM que usan este plugin para reservas. Un atacante podría acceder a cuentas administrativas y comprometer datos de clientes.