Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
15/06/2026
[CVE-2026-5230] Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library al…
Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-48610] Under certain network configurations, a malicious actor with access to network could exploit an Impr…
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47366] Improper verification of access permissions when modifying permissions through the Administration Co…
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.
N Alto vulnerabilidad
11/06/2026
[CVE-2026-44249] Netty is a network application framework for development of protocol servers and clients. In netty-h…
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.
P Alto vulnerabilidad
11/06/2026
[CVE-2026-45178] Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within i…
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20
A Alto vulnerabilidad
11/06/2026
[CVE-2025-46315] A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2…
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
V Alto vulnerabilidad
11/06/2026
[CVE-2026-41856] The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly re…
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 thr…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49822] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent surveillance channel over any other namespace. This issue has been patched in version 1.24.0.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49823] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types — Secret, ConfigMap, and Package. The first two were namespace-validated by the admission webhook; PackageRef.Namespace was not. This issue has been patched in version 1.24.0.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-49824] Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of …
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namespace equalled the function's own namespace but performed no equivalent check on spec.environment.name…
V Alto vulnerabilidad
10/06/2026
[CVE-2026-41728] Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-…
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
A Alto vulnerabilidad
09/06/2026
[CVE-2026-47907] Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerabili…
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-39169] SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-36720] Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from use…
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-49161] Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security f…
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48578] Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges l…
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45658] Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat…
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45649] Improper access control in Office for Android allows an unauthorized attacker to perform spoofing lo…
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45654] Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security fe…
Improper access control in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-42829] Improper access control in Windows Administrator Protection allows an authorized attacker to bypass …
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.