Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 869 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1045
Esta semana
RSS
M Alto vulnerabilidad
12/09/2026
[CVE-2026-81429] The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF c…
The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica en GitLab EE permite acceso a credenciales sensibles (CVE-2026-87719)
GitLab Enterprise Edition presenta una falla de seguridad en versiones 18.3 a 19.3.1 que permite a usuarios autenticados con acceso a Duo Chat obtener configuraciones de Advanced Search y credenciales sensibles mediante argumentos GraphQL especialmente diseñados. La vulnerabilidad afecta principalmente a empresas LATAM que utilizan GitLab EE para almacenar código crítico y secretos de aplicaciones. Con puntuación CVSS 9.9, esta falla requiere atención inmediata en infraestructuras de DevOps.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de traversal de directorios en libks anteriores a v2.0.11
libks, biblioteca fundamental para productos SignalWire C, contiene un defecto en la función `clean_uri()` del analizador HTTP que permite eludir la validación de rutas. Versiones anteriores a 2.0.11 no rechazarán URIs con segmentos de ruta excesivos, dejando secuencias ".." intactas y facilitando ataques de traversal de directorios. Esto afecta a cualquier aplicación que integre libks y procese solicitudes HTTP, comprometiendo el acceso a archivos sensibles en servidores de telecomunicaciones y plataformas de comunicaciones unificadas.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de condición de carrera en Hoverfly anteriores a v1.12.8
Hoverfly, herramienta de código abierto para simulación de APIs, presenta una vulnerabilidad de race condition en modo Diff que afecta escrituras concurrentes sin sincronización. Cuando múltiples solicitudes proxy se procesan simultáneamente, la función AddDiff() accede sin mutex al mapa compartido responsesDiff, causando fallos fatales en sistemas que dependen de esta herramienta para testing y desarrollo. Empresas en LATAM que usan Hoverfly en entornos de CI/CD o ambientes de validación de APIs están expuestas a interrupciones operacionales.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad en Melange y Apko permite instalar paquetes APK maliciosos sin validación
Melange versiones anteriores a 0.50.4 y Apko anteriores a 1.2.9 no verifican la integridad de los archivos de datos en paquetes APK durante la instalación, solo validan metadatos. Un atacante que controle un espejo, envenenene un caché o realice ataques MITM puede distribuir paquetes comprometidos que se instalarán sin detección. Afecta infraestructuras que utilizan estos gestores de compilación en entornos Linux containerizados.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89262] MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint…
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-89009] WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header wit…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78224] The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, …
The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.
M Crítico vulnerabilidad
11/09/2026
Vulnerabilidad crítica en Hugo v0.161.0+ permite ejecución de código mediante TailwindCSS
Hugo, generador de sitios estáticos, ejecuta herramientas Node con permisos insuficientemente restringidos desde la versión 0.161.0. TailwindCSS, incluido en la lista de seguridad por defecto, requiere configuraciones altamente permisivas (--allow-addons, --allow-child-process, --allow-worker) que permiten eludir controles de seguridad previos. Esto afecta a empresas en LATAM que alojan sitios web con Hugo y utilizan TailwindCSS para compilación de estilos.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XCS en plugin Kirki para WordPress afecta hasta versión 6.2.0
El plugin Kirki (Freeform Page Builder) para WordPress contiene una vulnerabilidad de Cross-Site Scripting almacenado (XSS) en el parámetro 'comment' que permite a atacantes no autenticados inyectar scripts maliciosos. La falta de sanitización de entrada y escapado de salida afecta todas las versiones hasta 6.2.0, comprometiendo sitios web de empresas, agencias digitales y plataformas de comercio electrónico en LATAM que utilizan este constructor de páginas.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-80469] Ejecución arbitraria de código mediante carga de controladores maliciosos
Una vulnerabilidad alta permite a atacantes ejecutar código arbitrario en sistemas objetivo cargando paquetes de controladores maliciosos que eluden mecanismos de verificación. El impacto afecta principalmente a infraestructuras empresariales en LATAM que utilizan dispositivos de hardware con controladores sin validación adecuada. Requiere interacción del usuario para su explotación.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de autenticación en WeenyGenius (CVE-2026-89176)
WeenyGenius, sistema de gestión de laboratorios informáticos de Howyar Technologies, presenta una vulnerabilidad de autenticación faltante (CVSS 8.8) que permite a atacantes en la misma red suplantar identidades de estudiantes o docentes sin credenciales. La suplantación de maestros compromete el control remoto de equipos estudiantiles, mientras que la de estudiantes interrumpe operaciones académicas normales. Instituciones educativas en México y LATAM con este software están expuestas en infraestructuras de redes cerradas o híbridas.
G Medio vulnerabilidad
11/09/2026
Chromium: CVE-2026-84330 UI misrepresentation in FullScreen
Microsoft publica advisory de seguridad: Chromium: CVE-2026-84330 UI misrepresentation in FullScreen.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-14563] The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before i…
The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including administrators, or to create arbitrary new accounts.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-81754] The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPres…
The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-77807] The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugi…
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45770] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua detection state and may bypass Suricata's restricted Lua sandbox. This requires an affected Lua script/rule to be loaded. Excessive flow variables being registere…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89086] In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm…
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89049] A server-side request forgery issue due to improper validation of equivalent address representations…
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role cre…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88021] Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh t…
Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape certain characters in service names, namespaces, and partitions, causing the generated authorization rules to match more broadl…