Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
N Alto vulnerabilidad
10/06/2026
[CVE-2026-52751] Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RM…
Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File → Open Project, deserializes untrusted objects using a Jython 2.7.4 gadget chain to execute arbitrary commands.
N Alto vulnerabilidad
10/06/2026
[CVE-2026-52752] Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails t…
Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Attackers can craft malicious extensions with traversal sequences like ../ in filenames to write arbitrary files outside the intended directory, enabling code execution.
N Alto vulnerabilidad
10/06/2026
[CVE-2026-52754] Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authen…
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise …
N Alto vulnerabilidad
10/06/2026
[CVE-2026-52755] Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that …
Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the intended theme directory. Attackers can craft malicious theme ZIP files with traversal sequences in filenames to execute arbitrary code or modify sensitive files like .bashrc or .ssh/authorized_keys.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49069] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.
N Alto vulnerabilidad
10/06/2026
[CVE-2026-49498] Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of Pos…
Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE statements. Authenticated attackers can inject SQL commands via crafted username parameters in PasswordChange network messages to escalate to PostgreSQL superuser privileges and gain full database cont…
I Alto vulnerabilidad
10/06/2026
[CVE-2025-71329] image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to …
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
I Alto vulnerabilidad
10/06/2026
[CVE-2025-71330] image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to …
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length f…
M Alto vulnerabilidad
10/06/2026
[CVE-2026-24066] Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.p…
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client's signing certificate and does not verify that the certificate chains to a trusted code-signing autho…
M Alto vulnerabilidad
10/06/2026
[CVE-2026-24067] Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.p…
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve code-signing information for the process. This PID-based client validation is subje…
M Alto vulnerabilidad
10/06/2026
[CVE-2026-3018] The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscrib…
The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries t…
M Crítico vulnerabilidad
10/06/2026
[CVE-2025-6254] The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, …
The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.
P Medio vulnerabilidad
10/06/2026
CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS
Palo Alto Networks PSIRT publica advisory de seguridad: CVE-2026-0267 GlobalProtect App: Information Exposure Vulnerability on macOS (Severity: MEDIUM). Tipo: Vulnerabilidad de seguridad. Producto afectado: GlobalProtect.
P Crítico vulnerabilidad
10/06/2026
CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
Palo Alto Networks PSIRT publica advisory de seguridad: CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux (Severity: MEDIUM). Tipo: Vulnerabilidad de seguridad. Producto afectado: Prisma Access.
P Medio vulnerabilidad
10/06/2026
CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing
Palo Alto Networks PSIRT publica advisory de seguridad: CVE-2026-0269 PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing (Severity: MEDIUM). Tipo: Denegación de Servicio (DoS). Producto afectado: PAN-OS.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
P Alto vulnerabilidad
10/06/2026
PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)
Palo Alto Networks PSIRT publica advisory de seguridad: PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026) (Severity: HIGH). Tipo: Vulnerabilidad de seguridad. Producto afectado: Palo Alto Networks.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-3326] The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before usi…
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
M Alto vulnerabilidad
10/06/2026
[CVE-2026-8071] The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize …
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated attackers to inject arbitrary web scripts into approved comments that will execute when any user (including administrators) views the post.
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-9067] The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilit…
The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos…
N Alto vulnerabilidad
10/06/2026
[CVE-2026-10846] NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolv…
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulne…