Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1841
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59127] Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privile…
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58641] Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally…
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58650] Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attack…
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58651] Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code …
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59113] Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a n…
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59119] Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privi…
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-56174] Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privilege…
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-56179] Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker…
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-57104] Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storag…
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-57105] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58612] Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to d…
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-54113] Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attack…
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-54981] Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension al…
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-54984] Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute c…
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-49179] Improper neutralization of special elements used in a command ('command injection') in Windows Activ…
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-50472] Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges loca…
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48438] CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in…
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48439] CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could…
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48440] ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary …
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48442] CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Director…
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is chang…