Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100255] In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possib…
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad de validación en OpenDMARC afecta autenticación de correo en servidores hasta versión 1.4.2
Se ha identificado una falla en Trusted Domain Project OpenDMARC versiones hasta 1.4.2 que permite eludir validaciones de equivalencia en el componente Domain Handler (archivo policy.c). La vulnerabilidad puede explotarse remotamente y afecta la autenticación DMARC de correos electrónicos en servidores de correo, con riesgo de suplantación de dominios. Empresas en LATAM que usan OpenDMARC deben aplicar actualizaciones urgentes, especialmente aquellas que procesan comunicaciones altas.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-86831] Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network P…
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions. To remediate this issue, users should upgrade to Amazon EKS Network Policy Agen…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-60074] Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that …
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit property `\p{Nd}` and not just `[0-9]`. Date::Manip::Base::check then validates the captured fields with numeric comparis…
M Alto vulnerabilidad
10/06/2026
[CVE-2026-42462] Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to v…
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature, allowing them to alter a third-party signed activity they have received. Versions …
R Alto vulnerabilidad
04/06/2026
[CVE-2026-49942] Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a…
Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such as the Arabic-Indic One (U+0661), or non-digits, which were ignored. This could allow network masks to accept larger networks. Leading zeros were also accepted, but treated as decimal instead of octal. This could lead to confusion about what networ…