Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Acer" — 18 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1797
Esta semana
RSS
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18089] Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses aga…
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured. verify_xml in Net::SAML2::Role::VerifyXML runs "return if !$anchors && !$cacert;" as soon as the XML::Sig check succeeds, and that check uses the X.509 certificate taken from the response's own dsig:KeyInfo/dsi…
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14893] IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer comp…
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65754] Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer…
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63685] Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator r…
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.
M Alto vulnerabilidad
17/07/2026
[CVE-2026-50273] Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Data…
Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on extraction, allowing a remote unauthenticated attacker to send a baggage header with many comma-separated key-value pairs or …
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8666] OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plug…
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50207] The system Binder boundary accepts unverified pass-through AT commands, giving local applications th…
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50209] Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (…
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50210] The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making …
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50213] The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, wh…
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-50205] System log files output unencrypted SMTP server authentication passwords alongside sensitive employe…
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49193] Overly permissive configuration settings on cloud storage containers expose active telemetry informa…
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49194] The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prom…
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49202] Internal multimedia session archives are accessible without authentication, exacerbated by loose Cro…
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49203] Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, …
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49190] The system fails to evaluate instructional permissions over multiple internal operation codes (opcod…
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49187] The hard-coded APK resource files never expire, and the shared scepter leads to information leaks an…
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49189] Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software c…
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.