Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-62104] Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
Unauthenticated Remote Code Execution (RCE) in Migratico Lite
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-62108] Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
Unauthenticated Broken Authentication in Headless Single Sign On
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-62101] Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Unauthenticated Broken Authentication in EduAdmin Booking
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica en rcourtman Pulse permite inyección de código remota
Se descubrió una falla de validación de entrada en rcourtman Pulse (versiones hasta 6.0.4 y 6.1.0-rc.4) en el componente Quick Security Setup Handler (/api/security/quick-setup). Un atacante remoto puede manipular el parámetro Username para ejecutar código arbitrario con CVSS 9.1. Afecta principalmente a servidores de autenticación y control de acceso en infraestructuras corporativas de México y LATAM.
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica de inyección de comandos en appliances FatPipe MPVPN, WARP e IPVPN
Los equipos FatPipe MPVPN, WARP e IPVPN con firmware 10.1.2r60p100 (fin de vida) contienen una vulnerabilidad de inyección de comandos OS en el demonio xtremed. Un atacante remoto no autenticado puede enviar entrada manipulada al endpoint AuthFormServlet para ejecutar comandos arbitrarios en el sistema, afectando la integridad de infraestructuras VPN críticas en empresas latinoamericanas. El CVSS de 9.8 refleja el riesgo extremo sin requerir autenticación previa.
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica en FatPipe MPVPN, WARP e IPVPN: desbordamiento de búfer remoto (CVE-2026-90823)
Los equipos FatPipe MPVPN, WARP e IPVPN con firmware 10.1.2r60p100 (fin de vida) contienen un desbordamiento de búfer en la interfaz de autenticación que permite ejecución remota de código sin credenciales. Un atacante puede enviar una solicitud manipulada contra la interfaz de gestión para comprometer completamente el dispositivo, poniendo en riesgo la conectividad WAN y acceso a datos corporativos en LATAM.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-88795] The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authenticat…
The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access it grants to write arbitrary files, leading to remote code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86707] The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate …
The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86709] The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session …
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-86710] The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in…
The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-87796] The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in …
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution poss…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-61594] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, na…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92805] UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wiza…
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92787] Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowin…
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-76460] A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, re…
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized ac…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-75513] Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9…
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a dictionary indexer key used by Where filters in src/Marten/Linq/Members/Dictiona…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20332] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Ad…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally disc…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20284] A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to co…
A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the unde…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-76423] A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remot…
A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request to the exposed REST API port. A successful exp…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20341] A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software cou…
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain&nbsp;root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management connection. An attacker could exploit this vulnerability by sending crafted sftunnel remote procedure calls (RPCs). A su…