Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-96207] Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to eleva…
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-95210] Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates cont…
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93291] Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-m…
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-85102] Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway…
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
M Crítico vulnerabilidad
08/09/2026
Vulnerabilidad crítica en hawtio-operator expone claves de firma de OpenShift
Se encontró una flaw en hawtio-operator que permite la lectura no autorizada de la clave privada de firma de la autoridad certificadora (CA) de servicios de OpenShift desde el namespace openshift-service-ca. Un atacante con permisos de creación de recursos Hawtio en cualquier namespace puede falsificar certificados de cliente con CN arbitrario, escalando privilegios en clústeres OpenShift. Esta vulnerabilidad afecta directamente a empresas en LATAM que ejecutan plataformas de contenedores en OpenShift.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-16822] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC p…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to impersonate the TNC policy server and modify traffic due to improper certificate validation.
M Crítico vulnerabilidad
19/08/2026
[CVE-2026-16835] IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and …
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-52723] ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to …
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the signed_vau_server_pub_keys and AUT_VAU_CertData certificate path to independent trusted material. A network-positioned attacker between…
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-66795] A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto…
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enab…
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-49457] erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not au…
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so `verify` was effectively a no-op on the client. A man-in-the-middle on the network path could pr…
M Crítico vulnerabilidad
01/08/2026
[CVE-2026-66402] FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity valid…
FreeRDP before 3.29.0 (affected versions
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-58162] The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled clien…
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-48021] In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between ep…
In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The …
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-11564] libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if …
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-45388] In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate pro…
In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
K Crítico vulnerabilidad
10/06/2026
[CVE-2026-53475] A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Sec…
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.