Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Microsoft" — 952 resultados ✕ Limpiar búsqueda
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-62316] Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t…
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through …
M Alto vulnerabilidad
Hace 2 días
CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-69855] Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di…
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-69558] Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized …
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
Hace 3 días
CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
Hace 4 días
CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
Hace 4 días
CVE-2021-41372 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2021-41372 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
CVE-2023-21806 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2023-21806 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
Hace 4 días
CVE-2024-43612 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2024-43612 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
Hace 4 días
CVE-2024-43481 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2024-43481 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-53958] 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an au…
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in server/api/controllers/users/update.js mass assigns these backend-managed identity att…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-50191] 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerabl…
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-60998] Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (componen…
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manage…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-74801] SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin…
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-69414] Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Micros…
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-50523] Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow…
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-72970] Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe…
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/08/2026
CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
13/08/2026
CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71331] Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation …
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.