Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 13 min
14,165
Total alertas
3233
Críticas
10659
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15560] when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs …
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15561] A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and cou…
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
M Alto vulnerabilidad
11/08/2026
CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
R Alto vulnerabilidad
11/08/2026
CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
11/08/2026
CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61936 Windows Defender Firewall Service Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
11/08/2026
CVE-2026-62899 .NET Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62899 .NET Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
11/08/2026
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
CVE-2026-64922 Microsoft SharePoint Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-64922 Microsoft SharePoint Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
11/08/2026
CVE-2026-65660 Microsoft SharePoint Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-65660 Microsoft SharePoint Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
11/08/2026
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
11/08/2026
CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
11/08/2026
CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
11/08/2026
[CVE-2026-16053] Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to A…
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-4757] A VAPIX API parameter had improper input validation which could allow code execution and potentially…
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-19424] Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability.…
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66763] SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated w…
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58243] SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality…
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44764] Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence…
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44765] Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence…
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, in…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58230] SAP Approuter does not sufficiently validate certain token content under specific configurations. An…
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality …