Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1741
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
Vulnerabilidad crítica en crate append-only-vec 0.1.9 de Rust permite ejecución remota de código
La dependencia maliciosa incluida en append-only-vec 0.1.9 ejecuta código arbitrario durante la compilación de proyectos Rust, estableciendo conexión con servidores de control remoto. Afecta directamente a desarrolladores y pipelines CI/CD en empresas de tecnología, fintech y servicios en LATAM que utilizan este componente. El CVSS 9.8 refleja acceso sin autenticación y control total del sistema comprometido.
M Crítico vulnerabilidad
Hace 3 días
Ejecución remota de código en SPIP anterior a 4.4.20 (CVE-2026-77647)
SPIP versiones anteriores a 4.4.20 contiene una vulnerabilidad crítica (CVSS 9.8) que permite a atacantes no autenticados ejecutar código arbitrario de forma remota, explotada activamente desde agosto de 2026. La falla radica en la identificación incorrecta de bloques PHP y el manejo deficiente de caracteres especiales por var_export. Afecta directamente a instituciones, medios digitales y PyMEs que usan SPIP como gestor de contenidos en la región.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-72843] The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/m…
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the cust…
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69555] Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne…
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69836] Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c…
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69851] Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat…
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-69400] Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a…
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-68782] Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da…
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-68789] Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da…
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65816] Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat…
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-66309] Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov…
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65801] Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e…
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-65770] Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed …
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-63509] Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over…
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-62834] Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack…
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-18835] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-17422] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-17157] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-17160] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-17136] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary cod…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.