Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-21273] is affected by an Improper Input Validation vulnerability that could result in privilege escalation.…
is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-21279] is affected by an Improper Input Validation vulnerability that could result in a Security feature by…
is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-71217] A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted cont…
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can …
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62295] HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J…
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising …
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62296] HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J…
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can t…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19177] Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a …
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19169] Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.…
Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-20273] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that ar…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-16793] An improper neutralization of special elements used in an operating system command vulnerability was…
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-69185] Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.…
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.
M Alto vulnerabilidad
02/08/2026
[CVE-2025-71399] Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3,…
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extr…
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta en GitPython anterior a 3.1.50 permite inyección de código remoto
GitPython versiones anteriores a 3.1.50 no valida correctamente caracteres de salto de línea en el parámetro section de config_writer(), permitiendo a atacantes inyectar encabezados arbitrarios en .git/config. Los adversarios pueden manipular la sección [core] para dirigir hooksPath hacia directorios controlados, logrando ejecución de código remoto cuando se activan hooks de Git. Esta vulnerabilidad afecta principalmente a repositorios compartidos y entornos de integración continua en empresas de México y Latinoamérica.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad de denegación de servicio en FreeRDP anterior a versión 3.29.0
FreeRDP versiones anteriores a 3.29.0 contiene una vulnerabilidad de denegación de servicio (DoS) en el manejador del canal RDPEI que no valida la longitud máxima del cuerpo PDU antes de asignar memoria. Un cliente RDP malicioso puede enviar un mensaje RDPEI solo con encabezado y una longitud de cuerpo declarada grande, forzando asignación excesiva de memoria en el servidor. Empresas en LATAM que utilizan FreeRDP en infraestructuras de acceso remoto deben actualizar inmediatamente para evitar interrupciones de servicios altas.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-53503] Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:co…
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for % and /) without validating columns > 0. When columns=0, the C code triggers undefined behavior; on x86_64 thi…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17930] Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 all…
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17888] Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed …
Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17867] Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a…
Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17861] Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowe…
Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17786] Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allow…
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17774] Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 all…
Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium)