Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-69183] Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-…
Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An unauthenticated attacker can rotate either header to create a new bucket for each request, bypassing rootRateLimiter, badAu…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76356] In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a …
In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Succ…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-6387] A potential authentication bypass vulnerability was reported in Lenovo System Update that could allo…
A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19291] Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x imp…
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-16101] Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue d…
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72809] SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the …
SiYuan versions
M Alto vulnerabilidad
12/08/2026
[CVE-2026-59916] Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Acc…
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-46731] Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentic…
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
M Alto vulnerabilidad
12/08/2026
[CVE-2025-59319] CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intende…
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high privilege.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-67558] The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a…
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-18639] When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a …
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-64665] Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, w…
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, without knowing that user's password, because the application matched OAuth identities to accounts by emai…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65570] Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
Unauthenticated Bypass Vulnerability in Login with phone number