Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Microsoft" — 1141 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-70178] Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a…
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-62906] Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows…
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84672] Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra …
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group.
M Alto vulnerabilidad
31/08/2026
CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
28/08/2026
[CVE-2026-72984] Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all…
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
28/08/2026
CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
G Alto vulnerabilidad
28/08/2026
CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability. Tipo: Suplantación (Spoofing).

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78915] Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjace…
Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)
M Alto vulnerabilidad
24/08/2026
CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
21/08/2026
[CVE-2026-62316] Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior t…
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through …
M Alto vulnerabilidad
21/08/2026
CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
20/08/2026
[CVE-2026-69855] Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to di…
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-69558] Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized …
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
20/08/2026
CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
19/08/2026
CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
19/08/2026
CVE-2021-41372 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2021-41372 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
19/08/2026
CVE-2023-21806 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2023-21806 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
19/08/2026
CVE-2024-43612 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2024-43612 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
19/08/2026
CVE-2024-43481 Power BI Report Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2024-43481 Power BI Report Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
18/08/2026
[CVE-2026-53958] 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an au…
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in server/api/controllers/users/update.js mass assigns these backend-managed identity att…