Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1815
Esta semana
RSS
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50225] The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious…
The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50214] The /v1/Plan service relies entirely on a shared global API token for full administrative management…
The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50208] High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-cod…
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50211] Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail buil…
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49191] The production build of the M3WebServer hard-codes its backend API keys, which can be easily interce…
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49188] The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), …
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49185] The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing…
The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-49186] The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any clie…
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.