Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 4 min
Buscando: "X" — 10435 resultados ✕ Limpiar búsqueda
14,046
Total alertas
3206
Críticas
10568
Altas
8
Ransomware
1046
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72534] A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta…
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group by name and replaces its membership without validating the source scope against t…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72536] A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remo…
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. An attacker can create payment intents and alter billing for any tena…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72537] A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an atta…
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attac…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-58231] SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and s…
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71217] A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted cont…
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72693] `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that use…
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`. `stat()` on `/proc//fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72694] A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops priv…
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. Thi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15554] the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any sh…
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
M Crítico vulnerabilidad
11/08/2026
CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62699 Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
R Medio vulnerabilidad
11/08/2026
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).
M Alto vulnerabilidad
11/08/2026
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
11/08/2026
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Medio vulnerabilidad
11/08/2026
CVE-2026-68802 Microsoft Excel Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-68802 Microsoft Excel Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
11/08/2026
CVE-2026-68808 Microsoft Excel Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-68808 Microsoft Excel Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
11/08/2026
CVE-2026-68813 Microsoft Excel Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-68813 Microsoft Excel Information Disclosure Vulnerability. Tipo: Divulgación de Información.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Medio vulnerabilidad
11/08/2026
CVE-2026-70318 Microsoft Excel Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70318 Microsoft Excel Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
11/08/2026
CVE-2026-70327 Microsoft Excel Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70327 Microsoft Excel Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
11/08/2026
CVE-2026-70328 Microsoft Excel Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70328 Microsoft Excel Information Disclosure Vulnerability. Tipo: Divulgación de Información.
G Crítico vulnerabilidad
11/08/2026
CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Crítico vulnerabilidad
11/08/2026
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).