Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49769] Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
Unauthenticated PHP Object Injection in wpForo Forum
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49085] Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formida…
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49104] Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForm…
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49105] Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidabl…
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49106] Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6…
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49109] Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elem…
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42687] Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
Unauthenticated PHP Object Injection in EventPrime

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39532] Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
Contributor PHP Object Injection in Events Calendar for GeoDirectory
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39498] Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
Shop manager PHP Object Injection in YayMail
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39499] Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6…
Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39474] Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
Contributor PHP Object Injection in Post Duplicator
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39478] Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versio…
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39481] Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
Author PHP Object Injection in Modula Image Gallery
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39471] Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Author PHP Object Injection in ShortPixel Image Optimizer
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39472] Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39434] Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
Shop manager PHP Object Injection in CTX Feed
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-27053] Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-27333] Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-39006] An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgS…
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
M Alto vulnerabilidad
14/06/2026
[CVE-2026-12191] A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pi…
A vulnerability was found in Comma AI Openpilot 0.11. This issue affects the function pickle.load/pickle.loads of the file selfdrive/modeld/modeld.py of the component Pickle Module. The manipulation results in deserialization. The attack is only possible with local access. The vendor was contacted early about this disclosure but did not respond in any way.