Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 12 min
Buscando: "Microsoft" — 1746 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57977] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ed…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57981] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57983] Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass …
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57984] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57985] Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exec…
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57986] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-56645] Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe…
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57974] Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to…
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-45499] Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileg…
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
02/07/2026
[CVE-2026-54998] Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privil…
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57100] Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an au…
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-41106] Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker …
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-50521] Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over…
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-45659] Vulnerabilidad explotada activamente en Microsoft SharePoint Server
CISA confirma explotación activa de una vulnerabilidad en Microsoft SharePoint Server. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-04.
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14124] Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.4…
Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Crítico vulnerabilidad
30/06/2026
[CVE-2026-14113] Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attack…
Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14122] Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 15…
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14094] Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attac…
Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14087] Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote at…
Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
30/06/2026
[CVE-2026-14060] Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.…
Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)