Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
14,926
Total alertas
3375
Críticas
11163
Altas
8
Ransomware
891
Esta semana
RSS
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77535] A malicious actor with access to the network and high privileges could exploit an Improper Input Val…
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77536] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77537] A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit…
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77538] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the UniFi Connect Application.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77539] A malicious actor with access to the network and high privileges could exploit an Improper Input Val…
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77540] A malicious actor with access to the network and high privileges could exploit an Improper Input Val…
A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-18794] The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory re…
The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19042] A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.8…
A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-59682] Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0…
Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-16444] Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.8…
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of th…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80235] EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthe…
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80236] Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated …
Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80237] EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authent…
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77533] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80233] CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File U…
CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-75977] The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Coo…
The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a WordPress user is logged in, combined with insufficient validation in mbw_validate_a…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-78236] An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to a…
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as an Apple-signed process.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-78237] Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into t…
Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective after the ABR session ended.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-18884] The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby'…
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existin…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-18331] The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin …
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …