Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
02/10/2026
[CVE-2026-96940] Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileg…
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-93355] LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT fro…
LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a token with an unverified email address matching a victim's account to inherit the vi…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94455] An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable withou…
An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on that list, so no authentication runs for these routes. The endpoint's only check is that the request body carries a token bearing a valid signature from the instanc…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77483] Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network…
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62895] Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker t…
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en hawtio-operator: escalación de privilegios en despliegues en cluster
Se descubrió una flaw en hawtio-operator que afecta despliegues en modo cluster. El operador crea un OAuthClient con aprobación automática sin secreto de cliente (cliente público), permitiendo que un tenant malicioso redirija URIs y realice ataques de suplantación de identidad. Esto expone sistemas en plataformas OpenShift y Kubernetes en México y LATAM a compromiso de credenciales y movimiento lateral en infraestructura containerizada.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65098] NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an at…
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-59554] Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
Unauthenticated Broken Authentication in Ziina
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50756] An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat…
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component