Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-106414] Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remo…
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-12342] This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code…
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API content.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-81995] Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that co…
Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-75686] Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitra…
Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-82008] Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could re…
Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
22/09/2026
Vulnerabilidad crítica en VeloCloud Orchestrator (VCO) on-prem permite acceso remoto no autorizado
VeloCloud Orchestrator (VCO) on-prem contiene una vulnerabilidad crítica (CVSS 10.0) que permite a atacantes remotos acceder a funcionalidades internas privilegiadas y comprometer la integridad del orquestador. La explotación exitosa impacta confidencialidad, integridad y disponibilidad de datos gestionados. Versiones hosted y dedicadas fueron afectadas, con implicaciones directas para proveedores de conectividad SD-WAN en México y LATAM que dependen de VCO para operaciones críticas.
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica en rcourtman Pulse permite inyección de código remota
Se descubrió una falla de validación de entrada en rcourtman Pulse (versiones hasta 6.0.4 y 6.1.0-rc.4) en el componente Quick Security Setup Handler (/api/security/quick-setup). Un atacante remoto puede manipular el parámetro Username para ejecutar código arbitrario con CVSS 9.1. Afecta principalmente a servidores de autenticación y control de acceso en infraestructuras corporativas de México y LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20237] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by C…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-53713] Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based…
Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lua submitted through EnvoyExtensionPolicy during default Strict validation. Linux resolves a double-s…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82441] Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `depend…
Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on the submission path, yet acts on them in two places. During cleanup of a finished topology, Nimbus deletes the keys named in those lists, and the deletion is perfo…
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-54694] SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code fl…
SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings directly into a template literal with no HTML entity encoding. `HighlightedValue.vue` renders that str…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69845] Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-68839] Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker …
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85047] Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82…
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84325] Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote a…
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81707] openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allow…
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing th…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-57499] Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vuln…
Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell command without sanitization, enabling shell escape via single-quote injection. …
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-59354] In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynami…
In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses a valid Initial Access Token can register a malicious client with crafted metadata, which, depending…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77552] A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit…
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-77554] A malicious actor with access to the network could exploit an Improper Input Validation vulnerabilit…
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.