Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1784
Esta semana
RSS
M Crítico vulnerabilidad
10/06/2026
[CVE-2025-6254] The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, …
The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() function not properly restricting the roles that a user can register with. This makes it possible for unauthenticated attackers to register as an administrator user.
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-9067] The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilit…
The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by WordPress's media library through endpoints that should only accept images or videos…
Q Crítico vulnerabilidad
10/06/2026
[CVE-2026-26241] A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can…
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later
Q Crítico vulnerabilidad
10/06/2026
[CVE-2026-26240] A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can…
A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5243 and later
Q Crítico vulnerabilidad
10/06/2026
[CVE-2025-66276] QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.…
QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later
E Crítico vulnerabilidad
10/06/2026
[CVE-2026-45328] ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, …
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA update…
A Crítico vulnerabilidad
09/06/2026
[CVE-2026-48303] Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Auth…
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-47938] Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Req…
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
A Crítico vulnerabilidad
09/06/2026
[CVE-2026-47928] ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnera…
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-36727] An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows…
An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-36721] A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 …
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-30141] An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function …
An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-10045] Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121,…
Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities allow attackers to read and write to memory, modify firmware stored in flash, inspect active connections, and view currently connected devices.
A Crítico vulnerabilidad
09/06/2026
[CVE-2026-34691] Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored C…
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control…
F Crítico vulnerabilidad
09/06/2026
[CVE-2026-49840] FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary …
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no sign or magnitude check. A malicious or man-in-the-middle ESL peer can send a frame…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
F Crítico vulnerabilidad
09/06/2026
[CVE-2026-49841] FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary …
FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded body but accepts Content-Length up to just under 10 MiB. The body-read loop is bo…
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-47643] External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute…
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-47291] Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code o…
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-45657] Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-47281] Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges ov…
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.