Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,949
Total alertas
3186
Críticas
10491
Altas
8
Ransomware
1138
Esta semana
RSS
M Alto vulnerabilidad
14/08/2026
[CVE-2026-72970] Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe…
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-73849] Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=r…
Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname, dbuser, dbpasswd, dbname, dbprefix, username, password, and email values to cause file_put_contents('config.php', $config) t…
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-48528] Metacat is data repository software that helps researchers preserve, share, and discover data. Metac…
Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input that can be passed through to the backend SQL database. The `nodeId` parameter can be modified to inject SQL commands, an…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19847] A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the functi…
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19679] An input validation vulnerability exists in Security Center's file upload handling, where insufficie…
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19680] A SQL injection vulnerability exists in Security Center that could allow an attacker to access unaut…
A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-19681] An authenticated command injection vulnerability exists in Security Center related to file upload pr…
An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
14/08/2026
[CVE-2026-19682] A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker…
A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19846] A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function s…
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-12366] Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an …
Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The cleanup switch handled only K_OBJ_MSGQ and K_OBJ_STACK; there was no K_OBJ_TIMER case. A dynamically-allocated, initialized, and armed k_timer keeps its embedded struct _timeout d…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19629] A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Secu…
A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19635] A local privilege escalation vulnerability exists in Security Center. An attacker with write access …
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-12364] The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was…
The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode implementation z_impl_z_log_msg_static_create() without performing any of the mandatory K_SYSCALL_* checks. Because z_log_msg_static_create() is declared __syscall, under CONF…
G Medio vulnerabilidad
14/08/2026
Chromium: CVE-2026-19560 Use after free in Blink
Microsoft publica advisory de seguridad: Chromium: CVE-2026-19560 Use after free in Blink.
G Medio vulnerabilidad
14/08/2026
Chromium: CVE-2026-19559 Use after free in HTML
Microsoft publica advisory de seguridad: Chromium: CVE-2026-19559 Use after free in HTML.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Medio vulnerabilidad
14/08/2026
Chromium: CVE-2026-19558 Use after free in Extensions
Microsoft publica advisory de seguridad: Chromium: CVE-2026-19558 Use after free in Extensions.
G Medio vulnerabilidad
14/08/2026
Chromium: CVE-2026-19557 Use after free in TabStrip
Microsoft publica advisory de seguridad: Chromium: CVE-2026-19557 Use after free in TabStrip.
G Medio vulnerabilidad
14/08/2026
Chromium: CVE-2026-19556 Use after free in V8
Microsoft publica advisory de seguridad: Chromium: CVE-2026-19556 Use after free in V8.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-46603] VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing …
VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-46439] compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 a…
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads i…