Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1815
Esta semana
RSS
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Azure Confidential Ledger permite ejecución de código remoto
Una función peligrosa expuesta en Azure Confidential Ledger permite que atacantes autorizados ejecuten código arbitrario a través de la red, afectando infraestructuras de blockchain y auditoría en empresas LATAM. Con CVSS 9.1, esta vulnerabilidad representa riesgo crítico para sistemas financieros, gubernamentales y de cumplimiento normativo que dependen de ledgers inmutables en Azure.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de escalada de privilegios en Microsoft Teams (CVE-2026-65667)
Microsoft Teams presenta una falla de autorización que permite a atacantes no autorizados escalar privilegios sobre la red con puntuación CVSS 10.0. Esta vulnerabilidad afecta directamente a organizaciones en México y Latinoamérica que dependen de Teams para comunicaciones empresariales y colaboración. El impacto potencial incluye acceso no autorizado a datos sensibles, comunicaciones y recursos compartidos dentro del ecosistema corporativo.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62873] Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorize…
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62896] Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over …
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-63508] Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthori…
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62830] Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a …
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-59115] '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to el…
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-59118] Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges…
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-50515] Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code…
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-56161] Improper access control in Azure Logic Apps allows an authorized attacker to disclose information ov…
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-56162] Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges …
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-50481] Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacke…
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-70558] Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directl…
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality check against a dinkyToken value whose default (efda1551-7958-4e0f-80a8-dfd107df3e38) is hardcoded i…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67622] Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assis…
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector s…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-53984] Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-in…
Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by sending a single full_restore command with a caller-supplied SQL blob. Attackers can connect to the Socket.IO server on port 700…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48085] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional GLOBAL_ADMIN accounts without verifying that an admin already exists. Any unauthenticated network attacker who can submit a same-or…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48086] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating their own tenant's staff. No policy check enforces that "only an existing GLOBAL…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48087] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the `userId` in the URL belongs to that email. An unauthenticated attacker requests a …
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-48088] OpenReception's appointment booking software provides an end-to-end encrypted appointment booking pl…
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication. The handler logs an "Unauthorized crypto key storage attempt" warning when neither …
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-3418] The System REST API accepts user-supplied file uploads without enforcing sufficient validation on th…
The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher privileges. Successful exploitation permits an authenticated publisher to upload files to server-accessible locations. Dependin…