Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95654] Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching …
Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept the invitation after the legitimate user has already accepted it to overwrite the account password and gain authenticated…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-75608] Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/…
Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for GET requests, exposing the proxied go2rtc API to viewer users. An authenticated viewer can request the streams, config, log, and stack subpaths to obtain internal a…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-6922] The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Aut…
The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.2.1. This is due to an operator precedence bug in the post-type guard within the trash_table_bulk() and restore_table_bulk() functions that causes the guard to never fire, combined with a permission callback that only verifies plugin role membership…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-77560] Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded …
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased hostname. The lookup in internal/service/access_controls_service.go through lookupStaticACLs and Get…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-80110] A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding…
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61672] Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenList…
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an administrator's forbidden list mixes capitalized and lowercase keys or otherwise has different case-insensitive and byte ordering, th…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93593] ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types becaus…
ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privilege user can read or insert TimeSeries samples despite explicit deny rules by exploiting the missing type-name-based access check that causes permission lookups to…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93594] ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-reco…
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user who is denied readRecord/deleteRecord on a type can still, with a single ordinary …
M Alto vulnerabilidad
17/09/2026
[CVE-2026-68791] Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose inform…
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92796] Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in mu…
Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that authenticate as administrators without plaintext recovery.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92801] cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler f…
cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the per-user access controls that protect the text message handler.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92788] Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes bel…
Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against other workspaces' memory databases to read, insert, or delete data.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92793] GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowi…
GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the admin prefix followed by /logout to reach administrative endpoints and perform unauthorized actions including reading sensitive data and modifying application state.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92782] Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allo…
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92776] Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, all…
Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-86043] Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the o…
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper truncates the body presented to Open Policy Agent because the input.truncated_body signal is derived from Content-Length rather than the actual read result. In filters/openpolicyagent/openpolicyagent.go, ExtractHttpBo…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27552] A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devic…
A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endpoint to upload IODD files to the device, potentially altering device behavior or causing system crashes.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-79708] GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 bef…
GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91735] Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker w…
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91734] Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a loca…
Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)