Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,538
Total alertas
3074
Críticas
10192
Altas
8
Ransomware
1802
Esta semana
RSS
A Crítico vulnerabilidad
21/07/2026
[CVE-2026-64606] Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypas…
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-64608] Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deseria…
Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of A…
M Crítico vulnerabilidad
20/07/2026
[CVE-2026-63767] ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserializa…
ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces. Attackers can exploit malicious __reduce__ methods embedded in crafted pickle payloads to execute arbitrary shell command…
W Alto vulnerabilidad
20/07/2026
[CVE-2026-28220] Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior …
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster key, to make the master node deserialize an attacker-controlled callable and execute it under an attacker-controlled RBAC c…
M Alto vulnerabilidad
19/07/2026
[CVE-2026-12484] A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-control…
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the abse…
L Crítico vulnerabilidad
17/07/2026
[CVE-2026-8476] IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the …
IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, integrity verification, or authentication, enabling arbitrary code execution when malicious pickle payloads are processed. Attackers who can…
M Alto vulnerabilidad
17/07/2026
[CVE-2026-45162] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, …
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from database columns and filesystem files without the allowed_classes restriction, including lib/Tool/Authentication.php, models/Site/Dao.php, models/DataObject/ClassDefinition/CustomLayout/Dao.php, models/Tool/TmpStore/Dao.php, models/Ass…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-14890] SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable netw…
SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote code execution when the feature is enabled and the service is reachable over the network.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15008] The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for …
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execu…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47472] NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attac…
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-24233] NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model we…
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50649] Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50646] Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local…
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55944] Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execu…
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50509] Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized…
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
S Alto vulnerabilidad
14/07/2026
[CVE-2026-45077] Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr…
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist,…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55009] Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elev…
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-54117] Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a…
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-54118] Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a…
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50652] Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny …
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.