Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 7 horas
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1031
Esta semana
RSS
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19291] Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x imp…
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19292] Re-pairing with a legitimate device can use a lower security level than previous making brute-forcin…
Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19293] SMP security request (from peripheral) does not include the maximum encryption key size supported. U…
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-16101] Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue d…
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
M Alto vulnerabilidad
13/08/2026
[CVE-2026-15994] During an internal security assessment, an improper link following vulnerability was identified in L…
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14456] Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packet…
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-12036] An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and…
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73188] Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
Unauthenticated Sensitive Data Exposure in KiviCare
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73346] Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66704] Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion
M Alto vulnerabilidad
13/08/2026
[CVE-2026-67986] amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code …
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application pa…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-67991] crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular…
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66697] Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCom…
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66698] Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
Unauthenticated Cross Site Scripting (XSS) in SureDash
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66700] Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66655] Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versi…
Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66656] Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
Unauthenticated Local File Inclusion in Foton Core
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66657] Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
Unauthenticated Local File Inclusion in Biagiotti Core
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66658] Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
Subscriber SQL Injection in Reviewer
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66661] Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
Subscriber Privilege Escalation in Directories Pro