Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,949
Total alertas
3186
Críticas
10491
Altas
8
Ransomware
1145
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70304 Windows DNS Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
11/08/2026
CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70330 Windows DNS Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Medio vulnerabilidad
11/08/2026
CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
11/08/2026
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability. Tipo: Manipulación (Tampering).
G Crítico vulnerabilidad
11/08/2026
CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70339 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Medio vulnerabilidad
11/08/2026
CVE-2026-59131 AMD Zen Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-59131 AMD Zen Information Disclosure Vulnerability. Tipo: Divulgación de Información.
R Medio vulnerabilidad
11/08/2026
CVE-2026-61360 Windows GDI Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61360 Windows GDI Information Disclosure Vulnerability. Tipo: Divulgación de Información.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
11/08/2026
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Medio vulnerabilidad
11/08/2026
CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-16053] Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to A…
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-4757] A VAPIX API parameter had improper input validation which could allow code execution and potentially…
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19516] A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re…
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-13716] Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authent…
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19425] Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability…
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-19424] Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability.…
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Medio vulnerabilidad
11/08/2026
CVE-2026-68146 ftrace: Add global mutex to serialize trace_parser access
Microsoft publica advisory de seguridad: CVE-2026-68146 ftrace: Add global mutex to serialize trace_parser access.
M Medio vulnerabilidad
11/08/2026
CVE-2026-68181 mei: bus: access mei_device under device_lock on cleanup
Microsoft publica advisory de seguridad: CVE-2026-68181 mei: bus: access mei_device under device_lock on cleanup.
M Medio vulnerabilidad
11/08/2026
CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate
Microsoft publica advisory de seguridad: CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66763] SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated w…
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58243] SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality…
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality…