Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-71302] The application accepts user-supplied session identifiers and does not regenerate the session ID aft…
The application accepts user-supplied session identifiers and does not regenerate the session ID after authentication. This allows an attacker to predefine a session ID and reuse it after victim authentication, resulting in session takeover.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-92609] Session fixation in HTTP management authentication allows remote attackers to gain unauthorized acce…
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-61687] Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale.…
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthenticated attacker to bind a victim's Hatchet session to an attacker-controlled OAuth identity. Explo…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92984] HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables inst…
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-77614] Opencast is a free, open-source platform to support the management of educational audio and video co…
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in. An unauthenticated attacker can send a crafted link to a victim…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-61592] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-1758] Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. T…
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-76196] Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege esca…
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-18527] IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow…
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-16496] The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the stream…
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.
M Crítico vulnerabilidad
27/07/2026
[CVE-2021-32088] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpo…
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-13707] Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated wit…
Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
M Alto vulnerabilidad
22/06/2026
[CVE-2026-56425] The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its …
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol. The application used the PHP session identifier (session_id()) as the OAuth state parameter. Because session identifiers are long-lived authentication credentials, exposing the…
M Alto vulnerabilidad
22/06/2026
[CVE-2026-12581] EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote a…
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.
M Crítico vulnerabilidad
09/06/2026
[CVE-2009-10007] Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixatio…
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
04/06/2026
[CVE-2025-67446] Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and …
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and gain unauthorized access to admin functionalities.