Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1018
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107612] Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local…
Incorrect permission assignment in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to read or overwrite the inter-process communication handles used between the TightVNC service and its desktop server process. The named shared memory segment in the Global\ namespace that carries the pipe HANDLE values is created with a NULL DACL, and its name is derived from a …
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-53953] GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of…
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-79901] In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Dire…
In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-94456] Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically…
Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these credentials depend entirely on V8’s deterministic xorshift128+ PRNG state. An unauthenticated OAuth dynamic client registration endpoint exp…
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta en NivoCart: tokens de restablecimiento predecibles permiten acceso administrativo
NivoCart versiones hasta 2.4.0 contiene una vulnerabilidad de severidad alta (CVSS 8.1) en el endpoint forgotten.php que genera tokens de recuperación predecibles usando substr(md5(mt_rand()), 0, 10). Un atacante que conozca el correo de un administrador puede solicitar un restablecimiento de contraseña, predecir el token y obtener acceso administrativo sin limitaciones de tasa ni expiración. Esta vulnerabilidad afecta directamente a plataformas de e-commerce en México y LATAM que utilizan NivoCart para gestionar tiendas en línea.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93868] Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.pas…
Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated attackers can read the server Date header, precompute candidate tokens within a narrow time window, and probe them against the passrecover authentication endpoint to reset any account pas…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92749] SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math…
SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp can regenerate the secret and forge valid administrator session cookies to gain control of protected sites.