Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 687 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69612] Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileg…
Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69564] Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized…
Heap-based buffer overflow in Windows Online Certificate Status Protocol (OCSP) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69513] Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi…
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69492] Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to e…
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69482] Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows …
Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69480] Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to e…
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69462] Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi…
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69450] Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges lo…
Out-of-bounds read in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69433] Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi…
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69436] Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi…
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69362] Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locall…
Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68894] Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privi…
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62810] Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized att…
Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84387] A improper neutralization of special elements used in a command ('command injection') vulnerability …
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84393] A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 thro…
A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82064] A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of servi…
A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. The server contains an assertion in its read concern processing logic that can be reached without authentication, and the assertion's assumptions about internal state do not hold for all member configurations, causing the server process to terminate.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73315] XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhoo…
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-33388] An access control vulnerability was discovered in the Credentials Manager functionality due to insuf…
An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges can view a limited subset of the available entries in the Credentials Manager. The actual credential values are not directly visible, but the user can delete entries or edit their properties. An attacker who d…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-33389] An improper certificate/host key validation vulnerability was discovered in the Smart Polling functi…
An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept …
M Alto vulnerabilidad
08/09/2026
Plugin Event Tickets and Registration para WordPress vulnerable a modificación no autorizada de credenciales Stripe
El plugin Event Tickets and Registration en WordPress (versiones hasta 5.27.4) presenta una falla alta de validación de permisos en el endpoint de retorno OAuth de Stripe, permitiendo que atacantes no autenticados sobrescriban credenciales del comerciante (tokens de acceso, claves públicas e ID de cuenta). Esto afecta directamente a tiendas en línea, plataformas de eventos y sitios de registro en México y LATAM que procesan pagos a través de Stripe.