Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-35283] Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (compon…
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Ca…
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-35284] Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (compon…
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Ca…
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-35285] Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (compon…
Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Ca…
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-35286] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter …
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-35268] Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Suppor…
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Identity Manager. While the vulnerability is in Identity Manager, attacks may significantly impact additional products (scope…
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-35270] Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Conten…
Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly im…
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-35263] Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Support…
Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-22313] The device has a webserver that exposes a REST API authenticated with a token on the management netw…
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
G Crítico vulnerabilidad
16/06/2026
[CVE-2026-0126] In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead …
In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-53776] Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass…
Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued bearer token can present expired tokens to any jwt.verify() call and retain authenticated access indef…
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12315] Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firef…
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12316] Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Th…
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12304] Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Fire…
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12293] Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Th…
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12294] Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox E…
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12295] Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefo…
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12296] Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefo…
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12297] Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability …
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-40750] Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store al…
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-52715] Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
Unauthenticated SQL Injection in GEO my WordPress