Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 9 horas
Vulnerabilidad alta de suplantación de identidad en GiveWP 4.16.8.1 y anteriores (CVE-2026-96333)
Se ha identificado una vulnerabilidad de omisión de autenticación en GiveWP (plugin de donaciones de Liquid Web/StellarWP) que permite a atacantes suplantar identidades y acceder a funcionalidades administrativas sin credenciales válidas. Afecta versiones hasta 4.16.8.1. Esto es alta para plataformas de recaudación, ONGs y organismos públicos en LATAM que utilizan este plugin en WordPress.
M Alto vulnerabilidad Nuevo
Hace 9 horas
Vulnerabilidad alta de omisión de autenticación en WPMU DEV Forminator (CVE-2026-96336)
Se ha identificado una vulnerabilidad de omisión de autenticación por suplantación de identidad en WPMU DEV Forminator que afecta versiones hasta 1.57.2. Esta falla permite a atacantes eludir mecanismos de autenticación en formularios, comprometiendo la integridad de datos y el acceso a aplicaciones web. Empresas en LATAM que utilizan este complemento en WordPress para gestionar formularios altas se encuentran en riesgo de acceso no autorizado.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107589] Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated…
Insufficient job validation for service accounts in Jacamar CI prior to v0.30.0 allows authenticated CI users to generate arbitrary account names.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-102161] An unauthenticated attacker located on an adjacent private network (or any attacker routed through a…
An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-41558] Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105741] Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10…
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol (MCP) configuration installation endpoint (POST /api/v1/mcp/project/{project_id}/install) allowed authenticated remote attackers to bypass the "local-only" access restriction. By sending a spoofed X-Forwarded-For: 127.0.0.1 header, an at…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105640] Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses return…
Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying that the provider authenticated ownership of the address. An attacker can set an OAuth identity's unverified provider email to a victim's address, which Plane matches directly to th…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104891] mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @in…
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrap…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-105215] ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1…
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-104988] A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when a…
A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream authorization checks to treat the request as agent-privileged. An authenticated EST use…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-94422] An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an a…
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox bound…
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de bypass de autenticación en YesWiki anteriores a 4.6.7
YesWiki antes de la versión 4.6.7 contiene una vulnerabilidad de bypass de autenticación en la bandeja de entrada ActivityPub que no vincula correctamente la firma HTTP verificada con el actor de la actividad. Atacantes no autenticados pueden utilizar cualquier par de claves ActivityPub para enviar actividades Delete o Update firmadas, permitiendo eliminar o sobrescribir entradas federadas de otros actores, especialmente en sistemas colaborativos y wikis corporativas.