Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-62834] Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack…
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica de omisión de autenticación en openssl_encrypt anteriores a v1.4.0
openssl_encrypt versiones previas a 1.4.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en pqc.py donde fallos en desencriptación AES-GCM activan una caída no autenticada a modo AES-CTR. Atacantes pueden modificar texto cifrado en tránsito para eludir verificación de integridad y ejecutar ataques de inversión de bits sin detección, comprometiendo confidencialidad e integridad de datos en sistemas financieros, gubernamentales y corporativos de LATAM.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt anteriores a 1.4.0 permite filtración de secretos
openssl_encrypt en versiones anteriores a 1.4.0 contiene una vulnerabilidad (CVSS 9.8) en la función PublicKeyBundle.from_dict() que procesa datos no verificados sin validar firmas criptográficas. Un atacante puede manipular bundles de claves públicas para cifrar datos con claves controladas por el atacante, exponiendo información sensible en bases de datos, sistemas de pago y plataformas cloud comúnmente utilizadas en LATAM.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-28148] Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated Bypass Vulnerability in Headless Single Sign On
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62873] Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorize…
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica CVE-2026-5430 en autenticación JWT permite acceso no autorizado
Múltiples fabricantes han reportado una vulnerabilidad crítica (CVSS 10.0) en mecanismos de autenticación JWT que aceptan tokens firmados con algoritmos no configurados explícitamente. Atacantes pueden falsificar tokens JWT con algoritmos alternativos que son validados incorrectamente, permitiendo acceso no autorizado a sistemas, bases de datos y controles administrativos. Este riesgo es especialmente grave en infraestructuras cloud, plataformas de API y soluciones de identidad ampliamente usadas en LATAM.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-7557] An improper verification of cryptographic signature vulnerability in the SAML authentication module …
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-9487] XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml()…
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document in which two elements share that ID value is accepted: the digest and signature are checked against w…
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-18108] Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_asser…
Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trus…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-44104] The firmware update process for the basemodule of the charging controller only validates the CRC32 c…
The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-59243] The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID …
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its de…