Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Zoom" — 16 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91792] When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layo…
When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application crash.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88285] Cámara GeoVision GV-LPC2211 V1.13 expone control PTZ sin autenticación
La cámara GeoVision GV-LPC2211 versión 1.13 expone un servicio de control PTZ (Pan-Tilt-Zoom) accesible por red sin requerir autenticación, permitiendo a atacantes remotos recuperar información de posicionamiento e inyectar comandos PTZ o comandos seriales arbitrarios. Esta vulnerabilidad afecta sistemas de vigilancia en infraestructura crítica, oficinas corporativas y centros de datos en México y Latinoamérica. Con CVSS 9.4, representa riesgo crítico de compromiso del perímetro de seguridad física y acceso no autorizado a sistemas de monitoreo.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite denegación de servicio en conexiones PTZ
GeoVision GV-LPC2211 versión 1.13 presenta una gestión inadecuada del estado de conexión PTZ (Pan-Tilt-Zoom) que permite a un atacante remoto no autenticado bloquear el bucle de aceptación y prevenir nuevas conexiones PTZ. Esta vulnerabilidad afecta sistemas de vigilancia altas en instalaciones de seguridad física en México y Latinoamérica, donde estas cámaras son ampliamente deployadas en bancos, hospitales y centros comerciales.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-53413] Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may a…
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-53415] Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve …
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-53416] Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information…
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-53411] A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation proces…
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/07/2026
[CVE-2026-53412] Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom …
Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-53409] Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authentica…
Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-53410] A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation proces…
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges.
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57712] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through
M Alto vulnerabilidad
17/06/2026
[CVE-2026-39597] Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor
Z Alto vulnerabilidad
12/06/2026
[CVE-2026-53408] Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for A…
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
Z Alto vulnerabilidad
12/06/2026
[CVE-2026-53407] Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for A…
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
Z Alto vulnerabilidad
12/06/2026
[CVE-2026-53406] Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows…
Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49069] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.