Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "X" — 7921 resultados ✕ Limpiar búsqueda
14,078
Total alertas
3213
Críticas
10592
Altas
8
Ransomware
1064
Esta semana
RSS
R Alto vulnerabilidad
14/07/2026
[CVE-2026-8313] A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the lin…
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15692] A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the functio…
A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15691] A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSaf…
A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-54429] A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices d…
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected applicatio…
E Alto vulnerabilidad
14/07/2026
[CVE-2026-15075] In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRe…
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. As a result, credential headers, including Authorization, Coo…
E Alto vulnerabilidad
14/07/2026
[CVE-2026-15076] In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession com…
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's domain, in violation of RFC 6265 section 5.3. An attacker who controls any server that the victim application contacts can inject a cookie scoped to an arb…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15416] A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could all…
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
R Alto vulnerabilidad
14/07/2026
CVE-2026-57097 Microsoft XML Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-57097 Microsoft XML Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15677] A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown funct…
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15676] A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted eleme…
A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15675] A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an un…
A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the argument UserId leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-12583] The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input tha…
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-58233] SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a…
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and ext…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-44745] SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under…
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the applic…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-44752] SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScr…
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integ…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-0487] SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from a…
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-56155] Vulnerabilidad explotada activamente en Microsoft Active Directory Federation Services
CISA confirma explotación activa de una vulnerabilidad en Microsoft Active Directory Federation Services. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-28.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-56164] Vulnerabilidad explotada activamente en Microsoft SharePoint Server
CISA confirma explotación activa de una vulnerabilidad en Microsoft SharePoint Server. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-17.
S Alto vulnerabilidad
14/07/2026
[CVE-2026-15409] Vulnerabilidad explotada activamente en SonicWall SMA1000 Appliances
CISA confirma explotación activa de una vulnerabilidad en SonicWall SMA1000 Appliances. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-17.
S Alto vulnerabilidad
14/07/2026
[CVE-2026-15410] Vulnerabilidad explotada activamente en SonicWall SMA1000 Appliances
CISA confirma explotación activa de una vulnerabilidad en SonicWall SMA1000 Appliances. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-17.