Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,459
Total alertas
3282
Críticas
10829
Altas
8
Ransomware
1095
Esta semana
RSS
M Alto vulnerabilidad
22/07/2026
[CVE-2026-14551] The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.…
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restric…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63047] Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Bo…
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
M Alto vulnerabilidad
22/07/2026
CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12987] The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data o…
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unau…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-3821] Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. …
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12968] The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not r…
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-15802] The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient …
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
C Alto vulnerabilidad
22/07/2026
[CVE-2026-16232] Vulnerabilidad explotada activamente en Check Point SmartConsole
CISA confirma explotación activa de una vulnerabilidad en Check Point SmartConsole. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-25.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-50522] Vulnerabilidad explotada activamente en Microsoft SharePoint
CISA confirma explotación activa de una vulnerabilidad en Microsoft SharePoint. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-25.
N Alto vulnerabilidad
21/07/2026
[CVE-2026-56819] Netty is a network application framework for development of protocol servers and clients. In version…
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`. When a `DATA` frame is processed for a str…
N Alto vulnerabilidad
21/07/2026
[CVE-2026-56820] Netty is a network application framework for development of protocol servers and clients. In version…
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an…
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16418] Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to ex…
Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16420] Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to exe…
Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16421] Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote a…
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16422] Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7…
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16423] Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convince…
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16413] Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who …
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16414] Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 al…
Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
M Alto vulnerabilidad
21/07/2026
[CVE-2026-65315] Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata …
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array counts that are used as allocation sizes without validation against remaining file size. Attackers …
M Alto vulnerabilidad
21/07/2026
[CVE-2026-65317] Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined wi…
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Ori…