Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,391
Total alertas
3276
Críticas
10807
Altas
8
Ransomware
1043
Esta semana
RSS
R Alto vulnerabilidad
14/07/2026
CVE-2026-57097 Microsoft XML Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-57097 Microsoft XML Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Medio vulnerabilidad
14/07/2026
CVE-2026-57976 Windows Active Directory Domain Services Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-57976 Windows Active Directory Domain Services Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).
M Medio vulnerabilidad
14/07/2026
CVE-2026-57979 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-57979 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
14/07/2026
CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-58614 Windows Kernel Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-58614 Windows Kernel Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Medio vulnerabilidad
14/07/2026
CVE-2026-33842 Windows File Explorer Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-33842 Windows File Explorer Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
14/07/2026
CVE-2026-34328 Windows Audio Service Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-34328 Windows Audio Service Information Disclosure Vulnerability. Tipo: Divulgación de Información.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Medio vulnerabilidad
14/07/2026
CVE-2026-40422 Windows File Explorer Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-40422 Windows File Explorer Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
14/07/2026
CVE-2026-41087 Windows File Explorer Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-41087 Windows File Explorer Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
14/07/2026
CVE-2026-34348 Windows Event Logging Service Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-34348 Windows Event Logging Service Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
14/07/2026
CVE-2026-44806 Windows Secure Channel Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-44806 Windows Secure Channel Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15677] A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown funct…
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15676] A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted eleme…
A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15675] A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an un…
A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the argument UserId leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-12511] The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using…
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-12583] The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input tha…
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-11563] The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file…
The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g. by deleting wp-config.php).
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-44761] SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials o…
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on conf…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-58233] SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a…
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and ext…
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-27690] Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could s…
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.