Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 31 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87016] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 un…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to SQL LIKE substring matching on SQLite. An OAuth subject containing percent or underscore wildcard characters could resolve to a different stored ident…
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad de autenticación en Parse Server <= 8.6.87 y 9.0.0-9.10.1 (CVE-2026-87806)
Parse Server contiene un bypass de autenticación en su adaptador LDAP integrado que permite a atacantes autenticarse sin credenciales válidas. El servicio acepta respuestas sin errores del directorio incluso cuando no se proporciona contraseña. Empresas en LATAM que usan Parse Server con LDAP en producción (principalmente startups y plataformas de datos) enfrentan riesgo alta de acceso no autorizado a sistemas y datos sensibles.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80099] Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because th…
Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request — performs an HMAC-style Bearer token comparison that degenerates when `HiiveConnection::g…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-76009] The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication By…
The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/wp-json/next_cart/v1/migration` REST route with `permission_callback` set to `__return_true` and relying on a hardcoded fallback value of `__token__` in `get_option…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86808] A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected elem…
A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 20260819.01 is sufficient to fix this issue. The…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86810] A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function…
A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version 1.10.0 is sufficient to resolve this issue. The patch is named 6fc91c49eebdb8bfdfe…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86669] A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login …
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not re…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-80097] Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privil…
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69854] Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges …
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86721] AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cook…
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86722] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vul…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86723] AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerabil…
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-79576] An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to …
An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-18922] A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried…
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect pas…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86306] A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601…
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made availab…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad de autenticación impropia en Tenda AC9 15.03.05.14 (CVE-2026-86300)
Se identificó un fallo en el manejador R7WebsSecurityHandler del componente de gestión web en routers Tenda AC9 versión 15.03.05.14 que permite eludir autenticación de forma remota. Esta vulnerabilidad de CVSS 7.3 afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos dispositivos en redes corporativas. El exploit ya está público, aumentando significativamente el riesgo de explotación.
M Alto vulnerabilidad
07/09/2026
CVE-2026-86292: Autenticación ausente en SourceCodester Simple Traffic Offense System 1.0
Se detectó una vulnerabilidad de autenticación faltante en SourceCodester Simple Traffic Offense System 1.0 en el archivo saveuser.php (componente User Creation). Un atacante remoto puede manipular el parámetro position para crear usuarios sin credenciales válidas, comprometiendo la integridad de sistemas de gestión de infracciones de tránsito. La vulnerabilidad tiene CVSS 7.3 y exploits públicos disponibles, representando riesgo alto para municipalidades y autoridades viales en LATAM que usan esta plataforma.
M Alto vulnerabilidad
06/09/2026
[CVE-2026-86214] A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown functio…
A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, n…
M Alto vulnerabilidad
06/09/2026
[CVE-2026-18056] The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the acc…
The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without p…
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-75816] The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Acco…
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as t…