Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-102167] On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's w…
On affected Arista Wi-Fi access points, a memory corruption vulnerability exists in access point's wired uplink network endpoints. An unauthenticated attacker can crash the sensor service or potentially achieve remote code execution. Exploitation requires the attacker to be on the same network segment as the access point's wired uplink.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101158] A missing input validation vulnerability in the Fileserver upload API allows an authenticated attack…
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-102155] An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application all…
An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-102159] An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access…
An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101152] Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated…
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101153] On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vul…
On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101154] An authenticated remote attacker with specific permissions can read or write files on the platform f…
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-101155] An authenticated remote attacker with specific permissions can read or write files on the platform f…
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101156] A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege adminis…
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensit…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101157] A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacen…
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82162] Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed En…
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-83550] A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints …
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from …
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-86360] Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Re…
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-86361] Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Criti…
Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-86362] Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A …
Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-63697] Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerabi…
Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-71168] Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Re…
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Remote execution.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-55330] In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a …
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-56906] In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could le…
In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106441] Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, …
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or facto…