Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,402
Total alertas
3280
Críticas
10814
Altas
8
Ransomware
1049
Esta semana
RSS
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16384] Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerabi…
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16385] Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerabi…
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16386] Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerabi…
Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16371] Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, …
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16372] Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefo…
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16373] Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed…
Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16374] Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firef…
Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16376] Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and…
Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16378] Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Fire…
Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16365] Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and …
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16366] Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 a…
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16362] Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Fi…
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16354] Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox …
Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
A Alto vulnerabilidad
21/07/2026
[CVE-2026-60080] Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Ap…
Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload could cause undefined behavior, process crash, or potential memory disclosure. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-1771] The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val…
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional check that prevents file validation from taking place. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on t…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-3183] Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authent…
Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-8082] The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter bef…
The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated attackers to perform time-based blind SQL injection on stores running this bpost-shipping-platform WordPress plugin before 3.2.3.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-11767] The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact f…
The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.
H Alto vulnerabilidad
21/07/2026
[CVE-2023-37507] HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus thei…
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-6952] A post-authentication command injection vulnerability in the "LogServer" field of the syslog compone…
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.