Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103490] In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92245] The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposur…
The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. This makes it possible for unauthenticated attackers to extract customer PII — including names, email addresses, phone numbers, and custom form field data — stored in appointment records, as well as per-appointment publ…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47580] NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacke…
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker could cause a missing authorization issue. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47559] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, w…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could access memory belonging to another user's process. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47552] NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unpri…
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass an authorization check and modify privileged configuration. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47493] NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a…
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100266] In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbit…
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97197] Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
Unauthenticated Broken Access Control in WordPress Backup & Migration
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96817] Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
Subscriber Broken Access Control in MakeCommerce for WooCommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96818] Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versi…
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments)
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96823] Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96348] Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
Unauthenticated Broken Access Control in Bookly
M Alto vulnerabilidad
30/09/2026
[CVE-2026-95587] Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
Unauthenticated Broken Access Control in Hostinger Migrator
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94499] Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
Subscriber Broken Access Control in FormGent
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94120] Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de Autorización en Qorela DC de Interprobe permite Escalada de Privilegios
Una vulnerabilidad de autorización faltante en Qorela DC (versiones 1.6.1-RC29 anteriores a 1.6.2) permite a usuarios autenticados elevar sus privilegios sin autorización adecuada. Afecta infraestructuras de centros de datos en México y Latinoamérica que utilicen esta plataforma de gestión. El CVSS 8.8 indica riesgo alta para la confidencialidad e integridad de sistemas altas.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización en REBUILD hasta v4.4.11 permite acceso no autorizado remoto
Se ha identificado una falla de seguridad en REBUILD versiones hasta 4.4.11 que afecta el módulo /commons/file-editor-save, permitiendo omitir controles de autorización mediante manipulación de parámetros (url/fileKey). Esta vulnerabilidad de severidad alta (CVSS 7.3) puede ser explotada remotamente y su código de ataque ya es público. Empresas en LATAM que usan REBUILD para gestión de contenidos están expuestas a acceso no autorizado a archivos sensibles.
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-49994] Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Blue…
Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* handlers (settings, devices, groups, per-device endpoints including /api/device/{mac}/notes) called no auth check at all. A network attacker reachable on the dashboard port could read Bluetooth tracking data and modify applica…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-82377] Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete…
Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belonging to other weblogs through the legacy XML-RPC Blogger and MetaWeblog APIs, because the handlers authenticate the caller but do not verify the caller's permission on the weblog or entry actually affected. Only installations that enable the non-default global XML-RPC setting ar…
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-101000] A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.…
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted ear…