Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
16/06/2026
[CVE-2026-8176] The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerab…
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39118] An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privilege…
An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-36213] An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges v…
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-12217] A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown f…
A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respon…
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12018] Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a l…
Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
P Alto vulnerabilidad
11/06/2026
[CVE-2026-45176] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within…
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actio…
A Alto vulnerabilidad
11/06/2026
[CVE-2025-31272] The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may …
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/06/2026
[CVE-2026-50570] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSafety admission webhook + sanitizeContainerSecurityContext executor merge layer), but the capability c…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-11616] The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in v…
The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before forwarding them to update_ayi_data(), which calls update_user_meta($current_user->…
M Alto vulnerabilidad
05/06/2026
[CVE-2025-5088] An authenticated Redis session could be used to obtain full root access to all servers in the CVX cl…
An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850.
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11296] Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remot…
Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-11103] Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed…
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49189] Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software c…
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.