Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad de enumeración de personal en Ghost 2.10.0 a 6.62.x permite fuga de datos sin autenticación
Ghost versiones 2.10.0 hasta 6.62.x contienen una vulnerabilidad en la API de contenido que permite a atacantes no autenticados enumerar miembros del personal y extraer información sensible analizando discrepancias en respuestas de metadatos. Afecta principalmente a plataformas de publicación y blogs empresariales en LATAM que utilizan Ghost como CMS, exponiendo datos de usuarios administradores y editores.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta de acumulación de memoria en Tornado anterior a 6.5.9
Tornado versions anteriores a 6.5.9 contienen una vulnerabilidad de acumulación ilimitada de memoria en CurlAsyncHTTPClient que permite a atacantes remotos causar denegación de servicio. Los atacantes pueden enviar bombas de descompresión gzip que se acumulan sin límites en memoria, provocando que el proceso de la aplicación sea terminado por condiciones de falta de memoria. Esto afecta directamente a aplicaciones web y APIs en producción que procesan respuestas comprimidas sin validación de tamaño.
M Crítico vulnerabilidad
01/10/2026
Vulnerabilidad crítica de autenticación en Fleet versiones anteriores a 4.87.0
Fleet antes de la versión 4.87.0 contiene una vulnerabilidad de omisión de autenticación en la API de dispositivos que permite a atacantes no autenticados usar nombres de host o números de serie como tokens válidos. Los atacantes pueden acceder a datos de dispositivos iOS/iPadOS, instalar software malicioso e iniciar migraciones MDM. Esta vulnerabilidad afecta empresas en LATAM que gestionan flotas de dispositivos móviles corporativos.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost 5.2.0 a 6.61.x permite inyección de contenido sin autenticación
Ghost versions 5.2.0 hasta anteriores a 6.62.0 contienen una vulnerabilidad que permite a atacantes remotos, sin autenticación, explotar el flujo de Stripe Checkout para adjuntar suscripciones pagas a miembros existentes, modificar nombres de usuarios e inyectar contenido malicioso en newsletters. El contenido inyectado puede ejecutarse como HTML o XSS dependiendo del cliente de correo, afectando principalmente a plataformas de publicación y membership en LATAM que utilizan Ghost para contenido de pago.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta de path traversal en n8n permite acceso no autorizado a workflows y credenciales
n8n versiones anteriores a 1.123.80, de 2.0.0 antes de 2.39.6 y de 2.40.0 antes de 2.40.1 contienen una vulnerabilidad de path traversal que permite a atacantes redirigir llamadas API a recursos no autorizados. Esto expone workflows, ejecuciones y secretos de credenciales dentro del alcance de la clave API, representando un riesgo alta para automatizaciones en producción en empresas LATAM que dependen de n8n para integraciones de negocio.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103259] n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in…
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103252] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an aut…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled host…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103253] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can inject single quotes in the table or schema fields to append arbitrary SQL statements and execute DDL or DML commands against the connected database with the credential's privileges.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103255] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103256] n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the …
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103247] n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs b…
n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can exploit mismatched node ID and name matching to retain victim credentials and redirect secrets to attacker-controlled hosts.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103248] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filt…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103249] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stor…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisti…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103250] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQ…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId parameter. Unauthenticated attackers can supply MongoDB query operators in the sessionId field to access conversation histories from other users and perform unauthorized write and delete operations.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103251] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a vali…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103082] Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor la…
Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103244] ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.res…
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103246] n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inl…
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and exfiltrate plaintext secrets to attacker-controlled hosts without ownership verification.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92144] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-96577] A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds …
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.