Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1781
Esta semana
RSS
M Alto vulnerabilidad
04/08/2026
Vulnerabilidad alta en Node.js HTTP/2 permite agotamiento de memoria remota
Un defecto en el manejo de HTTP/2 en Node.js permite que bloques de encabezados retenidos eludan el límite maxSessionMemory, facilitando ataques de denegación de servicio por exhaustión de memoria. Afecta Node.js versiones 24.x y 22.x, poniendo en riesgo aplicaciones web y APIs desplegadas en producción en data centers y servicios en la nube de LATAM.
M Alto vulnerabilidad
04/08/2026
Falla de validación de origen en Microsoft Edge permite divulgación de información
Se ha identificado una vulnerabilidad alta (CVSS 8.1) en Microsoft Edge basado en Chromium que permite a atacantes no autorizados eludir validaciones de origen y acceder a información sensible a través de la red. Esta falla afecta principalmente a empresas en México y LATAM que dependen de Edge como navegador corporativo, exponiendo datos de sesiones, credenciales y comunicaciones internas.
M Alto vulnerabilidad
04/08/2026
Vulnerabilidad alta de confusión de tipos en Microsoft Edge permite ejecución remota de código
Se ha identificado una vulnerabilidad de confusión de tipos (type confusion) en Microsoft Edge basado en Chromium que permite a atacantes ejecutar código arbitrario de forma remota con CVSS 7.4. Esta vulnerabilidad afecta potencialmente a millones de usuarios corporativos en México y Latinoamérica que utilizan este navegador en entornos empresariales, comprometiendo la seguridad de estaciones de trabajo y datos sensibles.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-66322] Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor…
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-66310] External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker …
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-66315] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-62870] Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a netw…
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-65802] External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker …
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-48399] Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability th…
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-10849] The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response…
The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL. When the full response has arrived, the code writes response_data[downloaded_size] = '\0' — and whenever …
M Alto vulnerabilidad
03/08/2026
[CVE-2026-69246] Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the req…
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable buil…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-41447] FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attack…
FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration file referencing an attacker-controlled DLL to achieve code execution at startup process privilege lev…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18647] A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8f…
A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may …
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18733] A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might…
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-69185] Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.…
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/08/2026
[CVE-2026-67599] ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows a…
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webcon…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-67598] Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/ser…
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSe…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18641] A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to…
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be uti…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-59912] Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Ac…
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-59913] Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Auth…
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.