Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 min
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71558] Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache For…
Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to den…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-71560] Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory…
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to…
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-16258] The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrust…
The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-16038] The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway …
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-14205] The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when re…
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
? Crítico alerta
07/08/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-8037.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de takeover de cuentas en plugin TrueBooker para WordPress (CVE-2026-14364)
El plugin TrueBooker para WordPress (versiones hasta 1.2.3) permite a atacantes no autenticados resetear contraseñas de usuarios arbitrarios mediante validación insuficiente de identidad. Afecta directamente a sitios de servicios (salones, clínicas, agencias) en LATAM que usan este plugin para reservas. Un atacante podría acceder a cuentas administrativas y comprometer datos de clientes.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin TrueBooker para WordPress
El plugin TrueBooker – Appointment Booking and Scheduler System para WordPress contiene una falla de autorización que permite a atacantes no autenticados cambiar contraseñas de cuentas administrativas en versiones hasta la 1.2.3. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan WordPress para gestión de citas y reservas, exponiendo el control total de sus sitios web.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de SSRF en Microsoft Office SharePoint permite acceso no autorizado
Una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en Microsoft Office SharePoint con puntuación CVSS 9.6 permite a atacantes no autorizados ejecutar solicitudes maliciosas y realizar suplantación de identidad en la red. Esta falla afecta directamente a infraestructuras colaborativas en empresas de México y LATAM que dependen de SharePoint para gestión de contenido y portal corporativo.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Azure Confidential Ledger permite ejecución de código remoto
Una función peligrosa expuesta en Azure Confidential Ledger permite que atacantes autorizados ejecuten código arbitrario a través de la red, afectando infraestructuras de blockchain y auditoría en empresas LATAM. Con CVSS 9.1, esta vulnerabilidad representa riesgo crítico para sistemas financieros, gubernamentales y de cumplimiento normativo que dependen de ledgers inmutables en Azure.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de escalada de privilegios en Microsoft Teams (CVE-2026-65667)
Microsoft Teams presenta una falla de autorización que permite a atacantes no autorizados escalar privilegios sobre la red con puntuación CVSS 10.0. Esta vulnerabilidad afecta directamente a organizaciones en México y Latinoamérica que dependen de Teams para comunicaciones empresariales y colaboración. El impacto potencial incluye acceso no autorizado a datos sensibles, comunicaciones y recursos compartidos dentro del ecosistema corporativo.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62873] Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorize…
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62896] Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over …
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-63508] Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthori…
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62830] Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a …
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-59115] '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to el…
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-59118] Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges…
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-50515] Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code…
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-56161] Improper access control in Azure Logic Apps allows an authorized attacker to disclose information ov…
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-56162] Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges …
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.