Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 23 min
14,138
Total alertas
3230
Críticas
10635
Altas
8
Ransomware
1006
Esta semana
RSS
M Alto vulnerabilidad
30/07/2026
[CVE-2026-41703] VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor w…
VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18378] A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resourc…
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18381] A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMe…
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-15397] The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all…
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action via the wps_sfw_install_plugin_configuration AJAX handler. This makes it possible for authenticated attackers, with shop manager-level access and above, to install a…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-22620] Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware…
Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-22621] Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PA…
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-22622] Improper input validation in one of the session management interface of Eaton's Tripp Lite series PA…
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18360] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18361] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16969] The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site sc…
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.
M Alto vulnerabilidad
30/07/2026
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44106] A privilege escalation vulnerability in the init-script for user-applications allows a low-privilege…
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44107] A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefor…
A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44099] A privilege escalation vulnerability in the system configuration allows a low-privileged local user …
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44093] A local privilege escalation vulnerability in the init-script for user-applications allows a low-pri…
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44094] An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with …
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44095] A privilege escalation vulnerability in a script used for network configuration allows a low-privile…
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44096] A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary …
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44097] A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endp…
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for firmware updates, resulting in persistent storage of attacker-controlled files and potentially exhausting resources, which might lead to Denial-of-Service.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44098] This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via …
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.