Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Microsoft" — 1139 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-84058] IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Micr…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.
M Alto vulnerabilidad Nuevo
Hace 20 horas
[CVE-2026-107782] System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc …
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107219] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier validation. OpenFile reaches agileDecrypt, which passes the unbounded spinCount to convertPasswdToKey before password verification. When a crafted OLE encrypt…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107217] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing na…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107214] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or ag…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107215] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107216] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-flight and iteration controls. ANCHORARRAY calls CalcCellValue instead of cellResolver, so each recursive hop receives a new calcContext and loses cycle st…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107212] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-101207] Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains a…
Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105791] Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P…
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attack…
M Alto vulnerabilidad
Hace 3 días
CVE-2026-72999 Windows USB Hub Driver Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-72999 Windows USB Hub Driver Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-96940] Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileg…
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
M Alto vulnerabilidad
29/09/2026
CVE-2026-57095 Win32k Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-57095 Win32k Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100208] Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execut…
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-70125] Microsoft Outlook Remote Code Execution Vulnerability
Microsoft Outlook Remote Code Execution Vulnerability

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-83598] Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Ag…
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair. Commands placed in that profile before repair therefore execute with SYSTEM privileges. This vulner…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88097] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privile…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-78501] Improper neutralization of special elements used in a command ('command injection') in Microsoft 365…
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
17/09/2026
CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-33835 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
15/09/2026
[CVE-2026-85893] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privile…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.