Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Microsoft" — 1141 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47296] Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a…
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47632] Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate pr…
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-48564] Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over…
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42975] Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execu…
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42982] Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized a…
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-44800] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40378] Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (L…
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40400] Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n…
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-42900] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.
F Alto vulnerabilidad
14/07/2026
[CVE-2026-59841] A improper restriction of communication channel to intended endpoints vulnerability in Fortinet Fort…
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via
M Alto vulnerabilidad
14/07/2026
CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49167 Windows Kernel Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49168 Storage Spaces Direct Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-45496 Visual Studio Code Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-45496 Visual Studio Code Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
14/07/2026
CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-55000 Windows USB Print Driver Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-54132 Windows Kernel Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-54132 Windows Kernel Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
CVE-2026-54108 Microsoft SharePoint Server Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-54108 Microsoft SharePoint Server Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
R Alto vulnerabilidad
14/07/2026
CVE-2026-57097 Microsoft XML Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-57097 Microsoft XML Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
14/07/2026
CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
14/07/2026
CVE-2026-58614 Windows Kernel Security Feature Bypass Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-58614 Windows Kernel Security Feature Bypass Vulnerability. Tipo: Bypass de Característica de Seguridad.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-0487] SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from a…
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.