Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
A Crítico vulnerabilidad
14/07/2026
[CVE-2026-48259] Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that coul…
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not re…
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-47428] Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Brow…
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin and recover VITEST_API_TOKEN for authenticated API calls. This issue is fixed in ve…
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-47429] Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on…
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could also allow arbitrary script execution. This issue is fixed in versions 3.2.5 and 4…
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-13001] The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to mi…
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
S Crítico vulnerabilidad
14/07/2026
[CVE-2026-47767] Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr…
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flag…
S Crítico vulnerabilidad
14/07/2026
[CVE-2026-45069] Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr…
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is …
S Crítico vulnerabilidad
14/07/2026
[CVE-2026-45063] Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr…
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside ano…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-57092] Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a networ…
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-56190] Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a …
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-56188] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-56159] Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55944] Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execu…
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55040] Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a secur…
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55010] Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to …
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50518] Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50447] Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod…
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50380] Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne…
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-15747] Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CS…
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed…
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-59891] sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, ge…
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because this is a substring match rather than an exact host match, credentials configured for one registry can be selected for an…
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55008] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.