Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50518] Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50447] Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod…
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-50380] Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne…
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-55008] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-54990] Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code …
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-49798] Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-49172] Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code ov…
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-48561] Improper neutralization of special elements used in a command ('command injection') in Copilot Chat …
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/07/2026
[CVE-2026-42990] Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code…
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
09/07/2026
[CVE-2026-47646] Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365…
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-58289] Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all…
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-45499] Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileg…
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57100] Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an au…
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-41106] Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker …
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-48584] Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate priv…
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-48582] Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileg…
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-45480] Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privile…
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
19/06/2026
[CVE-2025-62821] Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDat…
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call.
M Crítico vulnerabilidad
18/06/2026
[CVE-2026-54130] Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disc…
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
18/06/2026
[CVE-2026-47647] Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privilege…
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.