Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48572] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48581] Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to ele…
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49162] Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privilege…
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-45646] Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker…
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47296] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47632] Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate pr…
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-48561] Improper neutralization of special elements used in a command ('command injection') in Copilot Chat …
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48564] Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over…
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42975] Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu…
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42982] Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized a…
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-42990] Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code…
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-44800] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40378] Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (L…
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40400] Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n…
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42900] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Medio vulnerabilidad
14/07/2026
CVE-2026-34349 Windows Media Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-34349 Windows Media Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Medio vulnerabilidad
14/07/2026
CVE-2026-34346 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-34346 Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
14/07/2026
CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Medio vulnerabilidad
14/07/2026
CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability. Tipo: Divulgación de Información.