Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1261
Esta semana
RSS
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-78262] Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32563] Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 ver…
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32554] Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32555] Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-32559] Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Subscriber Arbitrary File Upload in UltimateAI
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76835] OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk…
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the s…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-71933] Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo…
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-71921] Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in …
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges.
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-71914] Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component.…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability via a crafted message to execute arbitrary commands with root privileges.
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-77915] rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthentica…
rConfig 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register route after it was explicitly disabled. Attackers can register a new account that is immediately authenticated with Admin-level …
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-19685] NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path d…
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogu…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76071] Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that al…
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verif…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76070] Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that al…
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote cod…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-19874] A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from …
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The functio…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76840] RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buff…
RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a remote file through cliprdr_send_request_filecontents and then executes CopyMemo…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-67602] phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows una…
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched column, enabling an entry written during an app_id lookup to satisfy a subsequent app_code lookup, allowing attackers to use…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-59568] Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code executio…
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-59564] An authentication bypass issue exists in communications between affected versions of the Zscaler Cli…
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
M Crítico vulnerabilidad
24/08/2026
Escalada de privilegios sin autenticación en Jawn <= 1.4.2 (CVSS 9.8)
Se ha identificado una vulnerabilidad crítica de escalada de privilegios sin autenticación en Jawn versión 1.4.2 y anteriores, con puntuación CVSS 9.8. Un atacante remoto puede explotar esta falla para obtener acceso administrativo sin credenciales válidas. Empresas en México y LATAM que utilicen Jawn en producción enfrentan riesgo inmediato de compromiso total del sistema.
M Crítico vulnerabilidad
24/08/2026
Inyección de Objetos PHP sin autenticación en FreightCo <= 1.1.15
FreightCo versiones 1.1.15 y anteriores contienen una vulnerabilidad crítica (CVSS 9.8) que permite inyección de objetos PHP sin requerir autenticación. Esta falla afecta directamente a empresas logísticas y de transporte en LATAM que utilizan esta plataforma para gestión de cargas, permitiendo a atacantes ejecutar código arbitrario y comprometer completamente los sistemas. La ausencia de controles de autenticación previos amplifica significativamente el riesgo de explotación remota.