Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
12/08/2026
[CVE-2026-67260] Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task…
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the sche…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48397] Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result…
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70321] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66808] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65815] Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attac…
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66805] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65663] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65665] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65658] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-64901] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-63514] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-59124] Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unaut…
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-17061] A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 20…
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-15555] A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicat…
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-68772] ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component…
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands wh…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71558] Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache For…
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to den…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-71559] Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an at…
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0.  Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71560] Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory…
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-16258] The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrust…
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-50515] Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code…
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.