Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-62073] Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.
Unauthenticated Broken Access Control in WP Full Stripe Free
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad de autenticación en Ghost anterior a 6.62.0 permite reactivación de cuentas suspendidas
Ghost versions anteriores a 6.62.0 contienen una vulnerabilidad que permite a usuarios del personal suspendido reactivar sus cuentas mediante restablecimiento de contraseña autogestionado. Un atacante con credenciales de staff suspendido puede ejecutar operaciones de restablecimiento de contraseña para recuperar acceso activo y restaurar privilegios originales, comprometiendo la integridad de sistemas de gestión de contenido en empresas de medios, agencias y plataformas editoriales en LATAM.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103251] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a vali…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without a…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103490] In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92245] The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposur…
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment publ…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47580] NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacke…
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47559] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, w…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47552] NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unpri…
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47493] NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a…
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100266] In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbit…
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97197] Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
Unauthenticated Broken Access Control in WordPress Backup & Migration
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96817] Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
Subscriber Broken Access Control in MakeCommerce for WooCommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96818] Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versi…
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments)
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96823] Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96348] Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
Unauthenticated Broken Access Control in Bookly

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-95587] Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
Unauthenticated Broken Access Control in Hostinger Migrator
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94499] Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
Subscriber Broken Access Control in FormGent
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94120] Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de Autorización en Qorela DC de Interprobe permite Escalada de Privilegios
Una vulnerabilidad de autorización faltante en Qorela DC (versiones 1.6.1-RC29 anteriores a 1.6.2) permite a usuarios autenticados elevar sus privilegios sin autorización adecuada. Afecta infraestructuras de centros de datos en México y Latinoamérica que utilicen esta plataforma de gestión. El CVSS 8.8 indica riesgo alta para la confidencialidad e integridad de sistemas altas.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización en REBUILD hasta v4.4.11 permite acceso no autorizado remoto
Se ha identificado una falla de seguridad en REBUILD versiones hasta 4.4.11 que afecta el módulo /commons/file-editor-save, permitiendo omitir controles de autorización mediante manipulación de parámetros (url/fileKey). Esta vulnerabilidad de severidad alta (CVSS 7.3) puede ser explotada remotamente y su código de ataque ya es público. Empresas en LATAM que usan REBUILD para gestión de contenidos están expuestas a acceso no autorizado a archivos sensibles.