Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 horas
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1055
Esta semana
RSS
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-55115] A malicious actor with access to the network and low privileges could exploit a Server-Side Request …
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-55116] A malicious actor with access to the network and under certain network configurations could exploit …
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-54400] A malicious actor with access to the network and high privileges could exploit an Improper Access Co…
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-54402] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-50746] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-50747] A malicious actor with access to the network and low privileges could exploit a series of authentica…
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-50748] A malicious actor with access to the network and low privileges could exploit an Improper Input Vali…
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-4767] Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allow…
Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-5524] The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote …
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is directly interpolated into a regular expression used to validate uploaded files. Atta…
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57683] Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
Unauthenticated SQL Injection in WP Fast Total Search
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57677] Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions…
Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57679] Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
Unauthenticated SQL Injection in GeekyBot
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57621] Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Unauthenticated PHP Object Injection in Booktics
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57623] Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
Unauthenticated Arbitrary Code Execution in W3 Total Cache
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57624] Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57625] Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 version…
Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-27436] Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Editor Arbitrary Code Execution in Five Star Business Profile and Schema
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-27419] Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
Subscriber Arbitrary File Upload in Zegen
G Crítico vulnerabilidad
01/07/2026
[CVE-2026-14425] Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potenti…
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
01/07/2026
[CVE-2026-14416] Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to pote…
Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)