Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1784
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-69543] Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat…
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69555] Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne…
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-69558] Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized …
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69836] Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c…
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69851] Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat…
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69400] Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a…
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-69419] Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to exe…
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-68782] Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da…
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-68789] Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da…
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-66800] Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose…
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65816] Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat…
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66309] Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov…
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65801] Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65770] Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed …
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-63509] Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over…
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-62834] Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack…
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-55765] CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. …
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pg_stat_statements was pr…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-55013] Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per…
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-49436] LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API…
LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrati…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-46355] BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebu…
BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse that participant's session and impersonate the participant in the same meeting b…