Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
27/07/2026
[CVE-2026-9830] The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its…
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13597] The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its …
The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an a…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-12255] The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site…
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-12493] The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify …
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by replaying a single genuinely-approved payment reference (for example one obtained f…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-13332] The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unaut…
The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-12877] The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not saniti…
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-62825] Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges ove…
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56191] Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tamp…
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-15981] The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in a…
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful sign…
P Alto vulnerabilidad
23/07/2026
[CVE-2026-10697] Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transf…
Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-15611] Logto allows unverified email-based SSO account linking, enabling an attacker to register an identit…
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-14291] The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication f…
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and bypass enforced two-factor authentication for any account, including administrators. The affected two-factor module ship…
O Crítico vulnerabilidad
22/07/2026
[CVE-2026-60367] Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen…
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result i…
M Crítico vulnerabilidad
22/07/2026
[CVE-2026-62144] An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security …
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a conf…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-62547] Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notific…
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base S…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-62534] Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: We…
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications F…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-62493] Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Opera…
Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing. Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Scor…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-62496] Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal …
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-62498] Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Intern…
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturin…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-62478] Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: …
Vulnerability in the Oracle Public Sector Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials. Successful attacks of this vulnerability can result in takeover of Oracle Publi…