Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61768] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61751] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61752] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61754] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61755] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61756] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61757] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61758] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61759] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-61750] NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of u…
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
M Crítico vulnerabilidad
31/08/2026
[CVE-2026-82226] Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
Unauthenticated PHP Object Injection in Tickera
M Alto vulnerabilidad
31/08/2026
[CVE-2026-83497] Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch …
Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-81757] Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de expansión de deserialización en SvelteKit 2.49.0 a 2.53.2 (CVE-2026-82259)
SvelteKit versiones 2.49.0 a 2.53.2 contienen un fallo de expansión de deserialización en la función experimental remoteFunctions. Atacantes pueden enviar entradas pequeñas que se expanden en arreglos de archivos masivos, causando agotamiento de memoria y denegación de servicio en aplicaciones web que procesan funciones remotas sin validar tamaños. El parche está disponible en versión 2.53.3.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82222] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injec…
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-78032] SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed…
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-14558] The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions …
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-10036] SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to…
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file w…
M Crítico vulnerabilidad
27/08/2026
Inyección de objetos PHP sin autenticación en Geo Controller <= 8.9.8
Se ha identificado una vulnerabilidad crítica (CVSS 9.8) de inyección de objetos PHP sin autenticación en Geo Controller versiones 8.9.8 y anteriores. Un atacante remoto podría ejecutar código arbitrario y comprometer completamente sistemas que utilicen esta extensión, afectando potencialmente aplicaciones web en infraestructuras de empresas y gobiernos en LATAM. La gravedad se debe a la ausencia de validación de autenticación previa al procesamiento de datos en el controlador Geo.
M Crítico vulnerabilidad
27/08/2026
Inyección de objetos PHP sin autenticación en Hash Form <= 1.4.1 (CVE-2026-78292)
Vulnerabilidad crítica (CVSS 9.8) en Hash Form versión 1.4.1 y anteriores permite inyección de objetos PHP sin requerir autenticación. Un atacante remoto puede ejecutar código arbitrario comprometiendo servidores web en empresas mexicanas y latinoamericanas. El riesgo es máximo en entornos de e-commerce, plataformas de gestión y aplicaciones expuestas a internet.