Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Microsoft" — 245 resultados ✕ Limpiar búsqueda
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62873] Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorize…
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-62896] Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over …
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62918] Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker …
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-63508] Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthori…
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-59115] '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to el…
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-59118] Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges…
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
C Alto vulnerabilidad
06/08/2026
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
CVE-2026-62869 Azure Entra ID Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-62869 Azure Entra ID Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
06/08/2026
CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Medio vulnerabilidad
06/08/2026
CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18485] There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.…
There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.
M Alto vulnerabilidad
04/08/2026
Falla de validación de origen en Microsoft Edge permite divulgación de información
Se ha identificado una vulnerabilidad alta (CVSS 8.1) en Microsoft Edge basado en Chromium que permite a atacantes no autorizados eludir validaciones de origen y acceder a información sensible a través de la red. Esta falla afecta principalmente a empresas en México y LATAM que dependen de Edge como navegador corporativo, exponiendo datos de sesiones, credenciales y comunicaciones internas.
M Alto vulnerabilidad
04/08/2026
Vulnerabilidad alta de confusión de tipos en Microsoft Edge permite ejecución remota de código
Se ha identificado una vulnerabilidad de confusión de tipos (type confusion) en Microsoft Edge basado en Chromium que permite a atacantes ejecutar código arbitrario de forma remota con CVSS 7.4. Esta vulnerabilidad afecta potencialmente a millones de usuarios corporativos en México y Latinoamérica que utilizan este navegador en entornos empresariales, comprometiendo la seguridad de estaciones de trabajo y datos sensibles.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-66322] Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor…
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-66310] External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker …
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/08/2026
[CVE-2026-66315] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-62870] Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a netw…
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-65802] External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker …
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
M Medio vulnerabilidad
03/08/2026
CVE-2026-50416 Win32k Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50416 Win32k Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
30/07/2026
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).