Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
A Alto vulnerabilidad
10/08/2026
iOS 26.6.1 (23G82)
Apple lanza actualización de seguridad para iOS versión 26.6.1. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Alto vulnerabilidad
10/08/2026
iPadOS 26.6.1 (23G82)
Apple lanza actualización de seguridad para iPadOS versión 26.6.1. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Alto vulnerabilidad
10/08/2026
macOS 26.6.2 (25G82)
Apple lanza actualización de seguridad para macOS versión 26.6.2. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Alto vulnerabilidad
10/08/2026
iOS 18.7.10 (22H373)
Apple lanza actualización de seguridad para iOS versión 18.7.10. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Alto vulnerabilidad
10/08/2026
iPadOS 18.7.10 (22H373)
Apple lanza actualización de seguridad para iPadOS versión 18.7.10. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-66403] DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor ma…
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-66405] DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be lever…
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/08/2026
[CVE-2026-66407] DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. …
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-64940] Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a pe…
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
M Alto vulnerabilidad
10/08/2026
CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
10/08/2026
CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18470] The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset requ…
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-18946] The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copyin…
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17022] The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's o…
The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17541] The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST…
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/08/2026
[CVE-2026-17542] The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its f…
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-14206] The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the e…
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19384] A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected…
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19387] A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element…
A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code ex…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-19389] Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly…
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information …