Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1784
Esta semana
RSS
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-70306] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-65791] Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execut…
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-62893] Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a…
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-62878] Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a ne…
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-62815] Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-59124] Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unaut…
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48362] ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS …
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-12571] An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeov…
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73080] SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/s…
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and no target validation, allowing anyone who can reach a volume server's gRPC port to cause requests to…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-73069] Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty al…
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72920] SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAcc…
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed i…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-17061] A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 20…
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48056] Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions p…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-46670] YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection i…
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72748] AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json…
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achiev…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-58115] A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions <…
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server. This could allow an unauthenticated remote attac…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-18972] An authenticated attacker can spoof another GUI user's identity by sending their request with the cu…
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
M Crítico vulnerabilidad
11/08/2026
Inyección de comandos OS en wg-easy 15.3.0 permite ejecución como root
Una vulnerabilidad crítica en wg-easy 15.3.0 permite a usuarios con permiso clients.create ejecutar comandos arbitrarios como root mediante inyección de directivas WireGuard malformadas en el campo de nombre del cliente. El software no sanitiza caracteres de salto de línea en la configuración, exponiendo servidores VPN corporativos en LATAM que utilicen esta herramienta de gestión. El acceso requerido es limitado, pero el impacto potencial es total compromiso del sistema.
M Crítico vulnerabilidad
11/08/2026
Inyección SQL crítica en e107 2.4.0 permite acceso no autenticado a bases de datos
Una vulnerabilidad de inyección SQL en e107 2.4.0 permite a atacantes no autenticados ejecutar comandos SQL arbitrarios a través del parámetro de ID de noticia, comprometiendo completamente la integridad de la base de datos. Los atacantes pueden leer, modificar o eliminar todos los contenidos, incluidas credenciales de administrador. Esta falla afecta directamente a portales de contenidos, sitios informativos y plataformas comunitarias desplegadas en LATAM sin parches aplicados.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-72550] An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated re…
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query() call, enabling stacked statement injection. An unauthenticated attacker can read, modify, or delete the entire database.