Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 41 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107615] An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8…
An uncontrolled search path element vulnerability in GlavSoft TightVNC Server for Windows before 2.8.88 allows a local authenticated user to execute arbitrary code with SYSTEM privileges. DynamicLibrary::init() (and ThemeLib) load screenhooks32.dll / screenhooks64.dll with LoadLibrary() using a bare file name and no LOAD_LIBRARY_SEARCH_* flags, so the TightVNC service follows the default DLL searc…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106186] Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0…
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 155.0.8059.39 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47570] NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA driver where an attacker …
NVIDIA GPU Display Driver for Windows contains a vulnerability in the CUDA driver where an attacker could cause a library to be loaded from an uncontrolled search path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-89325] An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windo…
An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Assessment content at or below version 0.0.261.0 included a check that invoked the `code` command without a fully qualified path from a process running as SYSTEM. The …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-6935] IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executabl…
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91803] A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to u…
A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-83598] Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Ag…
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulner…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
Escalada de privilegios por configuración débil en proceso de extracción de paquetes (CVE-2026-25264)
Se ha identificado una vulnerabilidad alta (CVSS 8.8) que permite escalada de privilegios mediante una configuración insegura durante la extracción de paquetes en múltiples productos. Esta vulnerabilidad afecta sistemas de distribución de software, contenedores y plataformas de despliegue comúnmente usadas en infraestructuras de empresas mexicanas y latinoamericanas. Un atacante podría obtener privilegios elevados en sistemas vulnerables durante procesos automatizados de actualización o instalación de dependencias.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54916] NetBox Device Type Library is a collection of community-sourced device type definitions for import i…
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenticated contributor can add a module such as tests/git.py that shadows GitPython when tests/definition…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-56795] Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element…
Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92838] A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The appli…
A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploited, an attacker with local write access to the affected directory could achieve …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92180] pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Priv…
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific fl…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-68955] The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link L…
The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the installation.