Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Microsoft" — 148 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 9 horas
CVE-2026-69566 Windows NTFS Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-69566 Windows NTFS Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Crítico vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-94510] Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attack…
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-96207] Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to eleva…
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-88131] Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute …
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
29/09/2026
[CVE-2023-54400] Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that al…
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with…
M Crítico vulnerabilidad
25/09/2026
CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-32157 Remote Desktop Client Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-69843] Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate pri…
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-77903] Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate …
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-69865] Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthori…
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
15/09/2026
[CVE-2024-58385] Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php…
Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can exploit this flaw to execute arbitrary SQL commands and, on Microsoft SQL Server deployments with xp_cmdshell enabled, write …
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87654] Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87621] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87528] Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attack…
Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87512] Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87494] Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote att…
Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-78509] Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute co…
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-78510] Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code …
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-77493] Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a n…
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69824] Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to …
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-69641] Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileg…
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.