Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
14,926
Total alertas
3375
Críticas
11163
Altas
8
Ransomware
888
Esta semana
RSS
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-32566] Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.6…
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-78137] The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on…
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-78333] The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submit…
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-77016] The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user'…
The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or contain the stored file path before deleting it, allowing users with a role as low as subscriber to delete arbitrary files on the server.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-77017] The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may s…
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-77018] The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may s…
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-59270] Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an a…
Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-47890] Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Event…
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-47891] A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not corr…
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47886] Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulner…
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47888] A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framewo…
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47889] A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies with…
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-47884] Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has…
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and ea…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47885] The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMe…
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47877] Spring Security Authorization Server's default consent page renders user-controlled values without H…
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47879] Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for d…
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-47849] Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation …
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-19715] The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access …
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-19223] The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network adminis…
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-13415] The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing se…
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administra…