Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Microsoft" — 1234 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1780
Esta semana
RSS
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49164] Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex…
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49165] Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo…
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49166] Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges loca…
Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49169] Use after free in DNS Server allows an authorized attacker to execute code over a network.
Use after free in DNS Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49170] Insufficient granularity of access control in Windows StateRepository API allows an authorized attac…
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48571] Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48572] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48581] Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to ele…
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49162] Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege…
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-45646] Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker…
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47296] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47632] Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate pr…
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-48561] Improper neutralization of special elements used in a command ('command injection') in Copilot Chat …
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48564] Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over…
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42975] Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu…
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42982] Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized a…
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-42990] Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code…
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-44800] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40378] Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (L…
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40400] Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n…
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.