Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20249] A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv…
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificat…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-58822] In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting…
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69585] Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacke…
Incorrect type conversion or cast in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
15/08/2026
Bypasa de autenticación en User Profile Builder para WordPress (CVE-2026-15826)
El plugin User Profile Builder para WordPress versiones hasta 3.16.4 contiene una vulnerabilidad crítica (CVSS 9.8) que permite bypasear autenticación mediante confusión de tipos en la función wppb_log_in_user(). Un atacante puede registrarse con nombres de usuario de 61-70 caracteres para eludir validaciones y acceder sin credenciales válidas. Afecta directamente a sitios WordPress en empresas LATAM que dependen de este plugin para gestión de usuarios y control de acceso.
M Alto vulnerabilidad
17/07/2026
[CVE-2025-51678] An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory add…
An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50337] Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate p…
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.
C Alto vulnerabilidad
07/07/2026
[CVE-2026-55076] Coder allows organizations to provision remote development environments via Terraform. Prior to vers…
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
O Alto vulnerabilidad
02/06/2026
[CVE-2026-45685] OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard…
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads …