Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1808
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71383] is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypa…
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71386] is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execut…
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71387] ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary co…
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70346] Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges…
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70347] Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges …
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70354] Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70355] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70335] Improper neutralization of special elements used in an os command ('os command injection') in GitHub…
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70336] Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthoriz…
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70337] Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code…
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70338] Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthor…
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70340] Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a…
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70344] Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges…
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70345] Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges …
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70324] Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70326] Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70329] Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execut…
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70321] Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex…
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70307] Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele…
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70311] Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.