Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-4104] Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Auto…
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50225] The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious…
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50214] The /v1/Plan service relies entirely on a shared global API token for full administrative management…
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50208] High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-cod…
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50211] Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail buil…
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
M Crítico vulnerabilidad
04/06/2026
Vulnerabilidad Crítica de Ejecución Remota de Código en Microsoft M365 Copilot (CVE-2026-45497)
Microsoft M365 Copilot es vulnerable a ejecución remota de código que permite a atacantes comprometer sistemas sin autenticación. Esta vulnerabilidad afecta directamente a empresas en México y LATAM que utilizan Copilot integrado en Microsoft 365 para procesamiento de documentos y análisis de datos sensibles. La explotación podría permitir acceso no autorizado a información confidencial, datos fiscales y comunicaciones empresariales.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49191] The production build of the M3WebServer hard-codes its backend API keys, which can be easily interce…
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49188] The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), …
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49185] The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing…
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49186] The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any clie…
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-41283] OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. The…
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
L Crítico vulnerabilidad
03/06/2026
[CVE-2026-46266] In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO…
In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW, 255); A malicious incoming ICMP packet can set the protocol field to 255 and match this socket, leading to FNHE cache changes. inner = IP(s…
L Crítico vulnerabilidad
03/06/2026
[CVE-2026-46244] In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 …
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), when processing inner IPv6 packets, ipv6_find_hdr() correctly computes the transport header offset traversing all extension headers, but the result is immediately overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only accounts for the IPv6 base h…
M Crítico vulnerabilidad
03/06/2026
[CVE-2026-36748] RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media link…
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
M Crítico vulnerabilidad
03/06/2026
[CVE-2026-36576] An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up …
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
C Crítico vulnerabilidad
03/06/2026
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
Cisco PSIRT publica advisory de seguridad: Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability. Tipo: Vulnerabilidad de seguridad. Producto afectado: Cisco. Security Impact Rating: Critical.
H Crítico vulnerabilidad
03/06/2026
[CVE-2026-5241] A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows…
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when lo…
M Crítico vulnerabilidad
03/06/2026
[CVE-2026-35075] An unauthenticated remote attacker can recover a default, hard coded password from a firmware image …
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
A Crítico vulnerabilidad
03/06/2026
[CVE-2026-47065] ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Pro…
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which perform…
A Crítico vulnerabilidad
03/06/2026
[CVE-2025-14771] Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue aff…
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.