Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87510] Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attack…
Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75991] Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary…
Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-75999] ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary …
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must ope…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-58941] In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input…
In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-55273] In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improp…
In AppendCommentLine of AnnotationProcessor.cpp, there is a possible supply chain risk due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78518] Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a …
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73021] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-72994] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-72996] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70573] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70581] Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate…
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69614] Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute co…
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69352] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69293] Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate pri…
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69295] Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally…
Out-of-bounds read in Windows USB Driver allows an authorized attacker to elevate privileges locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69270] Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized att…
Heap-based buffer overflow in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-79376] An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firm…
An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62647] A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generat…
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easi…
M Alto vulnerabilidad
07/09/2026
[CVE-2022-51017] PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submi…
PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-84469] fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthi…
fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handl…