Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
P Crítico vulnerabilidad
11/06/2026
[CVE-2026-45177] Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its int…
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the…
A Alto vulnerabilidad
11/06/2026
[CVE-2025-46315] A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2…
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
V Alto vulnerabilidad
11/06/2026
[CVE-2026-41856] The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly re…
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 thr…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-46695] Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and la…
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode, thereby gaining write access to that directory. This allows malicious code to perform …
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-50545] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fields into the generated pods. This issue has been patched in version 1.24.0.
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-50563] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-built podspec and creates a Deployment whose pods run the user's container image. This issue has been pat…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-50564] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs for runtime and builder pods. The merge logic propagated hostNetwork, hostPID, hostIPC, container privile…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49822] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent surveillance channel over any other namespace. This issue has been patched in version 1.24.0.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49823] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types — Secret, ConfigMap, and Package. The first two were namespace-validated by the admission webhook; PackageRef.Namespace was not. This issue has been patched in version 1.24.0.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49824] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namespace equalled the function's own namespace but performed no equivalent check on spec.environment.name…
M Crítico vulnerabilidad
10/06/2026
[CVE-2026-46614] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route — /fission-function/ and /fission-function// — for every Function object, independent of whether any HTTPTrigger exists for that function. The route was mounted on …
V Alto vulnerabilidad
10/06/2026
[CVE-2026-41728] Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-…
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
A Alto vulnerabilidad
09/06/2026
[CVE-2026-47907] Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerabili…
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-39169] SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-36720] Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from use…
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/06/2026
[CVE-2026-49161] Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security f…
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48578] Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges l…
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45658] Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat…
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45649] Improper access control in Office for Android allows an unauthorized attacker to perform spoofing lo…
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45654] Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security fe…
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.