Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
02/10/2026
[CVE-2026-96940] Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileg…
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93355] LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT fro…
LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the vi…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92288] Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow u…
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party. checkEndPointAuthenticationCredentials() skips the secret comparison for a Relying Party marked public and still returns the authentication method de…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94455] An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable withou…
An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on that list, so no authentication runs for these routes. The endpoint's only check is that the request body carries a token bearing a valid signature from the instanc…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77483] Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network…
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-73025] Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature ov…
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62895] Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker t…
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en hawtio-operator: escalación de privilegios en despliegues en cluster
Se descubrió una flaw en hawtio-operator que afecta despliegues en modo cluster. El operador crea un OAuthClient con aprobación automática sin secreto de cliente (cliente público), permitiendo que un tenant malicioso redirija URIs y realice ataques de suplantación de identidad. Esto expone sistemas en plataformas OpenShift y Kubernetes en México y LATAM a compromiso de credenciales y movimiento lateral en infraestructura containerizada.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-73819] The affected Ebyte product's vendor configuration utility permits access to administrative functi…
The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on the adjacent network could modify critical settings or change access credentials, potentially preventing legitimate administrators from managing the device.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65098] NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an at…
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-68067] The login endpoint on the Mira cloud API accepts any format-valid string in the password field and r…
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-59554] Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
Unauthenticated Broken Authentication in Ziina
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50756] An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat…
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55040] Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a secur…
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
P Crítico vulnerabilidad
10/06/2026
[CVE-2026-0274] An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Corte…
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-6274] Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerabi…
Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.