Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta en Pake: acceso IPC no restringido expone aplicaciones Tauri
Pake, herramienta que convierte sitios web en aplicaciones de escritorio basadas en Tauri, genera aplicaciones que heredan configuraciones inseguras que otorgan acceso IPC (Inter-Process Communication) a cualquier origen HTTPS mediante un patrón comodín. Esta vulnerabilidad permite que contenido web no confiable ejecute funcionalidad nativa del sistema, afectando potencialmente a empresas en LATAM que distribuyen aplicaciones generadas con Pake sin validar sus configuraciones de seguridad.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-78501] Improper neutralization of special elements used in a command ('command injection') in Microsoft 365…
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87734] An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly …
An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62836] Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance al…
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-23904] Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to th…
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.1…
F Alto vulnerabilidad
14/07/2026
[CVE-2026-59841] A improper restriction of communication channel to intended endpoints vulnerability in Fortinet Fort…
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via
J Alto vulnerabilidad
09/07/2026
[CVE-2026-57028] An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Netw…
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized acc…