Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 10641 resultados ✕ Limpiar búsqueda
14,402
Total alertas
3280
Críticas
10814
Altas
8
Ransomware
1048
Esta semana
RSS
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16363] JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox…
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16364] Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed i…
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16349] Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox …
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16350] Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in F…
Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16351] Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed …
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16352] Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was…
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16353] Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153…
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16354] Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox …
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-65008] Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData…
Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because the form plugin routes page frontmatter through this path, an authenticated account with the admin.pages (or api.pages.writ…
A Alto vulnerabilidad
21/07/2026
[CVE-2026-60080] Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Ap…
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
A Crítico vulnerabilidad
21/07/2026
[CVE-2026-64606] Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypas…
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-62415] Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Jo…
Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-11767] The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact f…
The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-6952] A post-authentication command injection vulnerability in the "LogServer" field of the syslog compone…
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16332] A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /…
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16329] A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file …
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16330] A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function …
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could b…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16331] A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function…
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
N Alto vulnerabilidad
21/07/2026
[CVE-2026-55833] Netty is a network application framework for development of protocol servers and clients. Prior to 4…
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has exceeded `maxHeaderSize` and marked the frame truncated in `SpdyFrameCodec`, allowing a remote peer to send a small compressed `HEADERS` block that expands into…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16327] A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing o…
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.