Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 min
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1773
Esta semana
RSS
M Alto vulnerabilidad
04/06/2026
[CVE-2019-25726] All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated …
All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id parameter to extract sensitive database information including usernames, databases, and version detail…
H Alto vulnerabilidad
04/06/2026
[CVE-2025-52612] HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflect…
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .
M Alto vulnerabilidad
04/06/2026
[CVE-2026-10840] A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBi…
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete…
M Alto vulnerabilidad
04/06/2026
[CVE-2026-10843] A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator…
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential compromise.
F Alto vulnerabilidad
04/06/2026
[CVE-2025-12694] A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-a…
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.
M Alto vulnerabilidad
04/06/2026
[CVE-2026-49771] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Gallery by 10Web allows Blind SQL Injection. This issue affects Photo Gallery by 10Web: from n/a through 1.8.41.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50207] The system Binder boundary accepts unverified pass-through AT commands, giving local applications th…
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50209] Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (…
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50210] The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making …
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50213] The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, wh…
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
M Alto vulnerabilidad
04/06/2026
[CVE-2026-3820] There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attack…
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation. Potential impact includes denial-of-service attacks, arbitrary code execution, or perman…
M Alto vulnerabilidad
04/06/2026
Vulnerabilidad de Elevación de Privilegios en Azure HorizonDB (CVE-2026-48567)
Se ha identificado una vulnerabilidad de elevación de privilegios en Azure HorizonDB que permite a usuarios con acceso limitado escalar permisos en el servicio. Este tipo de falla afecta directamente a empresas en México y Latinoamérica que utilizan HorizonDB en entornos de producción para bases de datos críticas. La explotación podría comprometer la confidencialidad e integridad de datos sensibles almacenados en Azure.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50205] System log files output unencrypted SMTP server authentication passwords alongside sensitive employe…
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49193] Overly permissive configuration settings on cloud storage containers expose active telemetry informa…
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49194] The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prom…
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49202] Internal multimedia session archives are accessible without authentication, exacerbated by loose Cro…
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49203] Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, …
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49190] The system fails to evaluate instructional permissions over multiple internal operation codes (opcod…
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49187] The hard-coded APK resource files never expire, and the shared scepter leads to information leaks an…
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49189] Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software c…
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.