Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 31 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
05/09/2026
Escalación de privilegios alta en plugin Abandoned Cart Pro para WooCommerce
El plugin Abandoned Cart Pro para WordPress contiene una vulnerabilidad de escalación de privilegios (CVSS 8.8) que afecta todas las versiones hasta la 10.7.1. Usuarios autenticados pueden ejecutar acciones administrativas sin verificación de capacidades o nonces, comprometiendo tiendas de comercio electrónico en la región. La vulnerabilidad impacta acciones AJAX altas de configuración y envío de correos, exponiendo datos sensibles de clientes y carros abandonados.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-75160] An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via th…
An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-15354] The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,…
The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling `wp_update_user()`. This makes it possible for unauthenticated attackers to overwrite any WordPress user's email address…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85154] WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a…
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the credential remains valid even after the owner changes…
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Craft CMS anterior a 5.10.11 permite escalación de privilegios
Craft CMS versiones anteriores a 5.10.11 no valida correctamente la bandera de administrador durante el registro de usuarios, permitiendo que atacantes hereden permisos administrativos registrándose con direcciones de correo de cuentas administrador desactivadas. Esta vulnerabilidad afecta especialmente a instancias con registro público habilitado y verificación de correo desactivada, exponiendo sistemas de gestión de contenidos en empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-80467] The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role subm…
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities and then escalate it to administrator.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19453] The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the acco…
The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it preserves across a restore or migration before granting it administrator privileges, allowing a subscriber-level user to gain administrator access after the site owner restores or migrates the site.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-9055] The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerab…
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when t…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84115] A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown functio…
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 i…
M Crítico vulnerabilidad
01/09/2026
Escalada de privilegios crítica en tema WordPress Nokri - Validación insuficiente de tokens
El tema WordPress Nokri Job Board contiene una vulnerabilidad de escalada de privilegios en versiones hasta 1.6.6 que permite a atacantes no autenticados tomar control de cuentas de usuario. La falla radica en validación deficiente de tokens de reinicio de contraseña en la función `nokri_reset_password()`, que acepta tokens vacíos coincidiendo con valores de metadata desconfigurados. Esto afecta directamente a empresas de LATAM que operan portales de empleo en WordPress, exponiendo bases de datos de candidatos y datos administrativos.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-79744] MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/AP…
MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no authorization check. It is protected only by the app-wide authentication middleware and a rate limiter — it never inspects req.user.…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82807] A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown …
A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond…
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82860] @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence…
@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82857] hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration…
hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82628] A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function …
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/08/2026
Escalada de Privilegios Crítica en Plugin Custom User Registration Fields para WooCommerce (CVE-2026-15369)
El plugin Custom User Registration Fields para WooCommerce (versiones hasta 2.2.3) permite a atacantes no autenticados escalar privilegios mediante manipulación del parámetro afreg_select_user_role en la API /wc/store/v1/checkout. Esta vulnerabilidad afecta directamente tiendas en línea alojadas en servidores WordPress en México y LATAM, permitiendo que usuarios no autenticados asuman roles administrativos sin validación. El CVSS 9.8 indica riesgo crítico con alcance de red y sin requerimientos de autenticación.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-79996] The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability chec…
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-19423] The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection whe…
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant thems…