Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3697 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1856
Esta semana
RSS
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en V-Secure Jingyun Antivirus 2.4.2.39 permite escalada de privilegios
Se ha identificado una vulnerabilidad de control de acceso impropio en el controlador de kernel ZyArk.sys de V-Secure Jingyun Antivirus versión 2.4.2.39 (CVSS 7.8). Esta falla requiere acceso local pero permite que un atacante escale privilegios en sistemas Windows. El exploit está públicamente disponible y el fabricante no ha respondido a la divulgación responsable, lo que aumenta el riesgo inmediato para empresas en México y LATAM que usan este antivirus.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin TrueBooker para WordPress
El plugin TrueBooker – Appointment Booking and Scheduler System para WordPress contiene una falla de autorización que permite a atacantes no autenticados cambiar contraseñas de cuentas administrativas en versiones hasta la 1.2.3. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan WordPress para gestión de citas y reservas, exponiendo el control total de sus sitios web.
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad de escalada de privilegios en StableBit Scanner 2.6.13.4088
Se identificó una debilidad en el servicio ScannerService de StableBit Scanner versión 2.6.13.4088 que permite manipulación de permisos mediante ejecución local en sistemas Windows. El exploit público incrementa el riesgo para empresas en LATAM que utilizan este software de monitoreo de almacenamiento. La vulnerabilidad afecta principalmente servidores y estaciones de trabajo con acceso local no restringido.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-49746] Software installed and run as a non-privileged user may conduct improper GPU system calls to cause O…
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-45198] Kernel software from a non-secure operating system on a platform with Trusted Execution Environment …
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main mem…
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad de escalada de privilegios en PowerISO 9.3.0.0 (CVE-2026-19189)
Se ha descubierto una flaw de seguridad en PowerISO versión 9.3.0.0 que afecta el controlador de kernel scdemu.sys, permitiendo escalada impropia de privilegios. El exploit está público y requiere acceso local a la máquina. Empresas en LATAM que usen esta herramienta para virtualización o gestión de imágenes ISO deben evaluar el riesgo inmediato en estaciones de trabajo y servidores, especialmente en entornos donde usuarios estándar comparten equipos.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de SSRF en Microsoft Office SharePoint permite acceso no autorizado
Una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en Microsoft Office SharePoint con puntuación CVSS 9.6 permite a atacantes no autorizados ejecutar solicitudes maliciosas y realizar suplantación de identidad en la red. Esta falla afecta directamente a infraestructuras colaborativas en empresas de México y LATAM que dependen de SharePoint para gestión de contenido y portal corporativo.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica en Azure Confidential Ledger permite ejecución de código remoto
Una función peligrosa expuesta en Azure Confidential Ledger permite que atacantes autorizados ejecuten código arbitrario a través de la red, afectando infraestructuras de blockchain y auditoría en empresas LATAM. Con CVSS 9.1, esta vulnerabilidad representa riesgo crítico para sistemas financieros, gubernamentales y de cumplimiento normativo que dependen de ledgers inmutables en Azure.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de escalada de privilegios en Microsoft Teams (CVE-2026-65667)
Microsoft Teams presenta una falla de autorización que permite a atacantes no autorizados escalar privilegios sobre la red con puntuación CVSS 10.0. Esta vulnerabilidad afecta directamente a organizaciones en México y Latinoamérica que dependen de Teams para comunicaciones empresariales y colaboración. El impacto potencial incluye acceso no autorizado a datos sensibles, comunicaciones y recursos compartidos dentro del ecosistema corporativo.
M Crítico vulnerabilidad
07/08/2026
[CVE-2026-50515] Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code…
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-7867] A flaw was found in udisks2. A local attacker with an active console session can exploit insufficien…
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation th…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-8325] A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write…
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-7406] A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted…
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-71488] league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2…
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate…
C Medio vulnerabilidad
06/08/2026
[CVE-2026-71433] LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of L…
LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string as a simple prefix pattern, so a read scoped to one namespace could also match a s…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70635] TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability th…
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70636] Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated at…
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70638] llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android …
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70640] llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LL…
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijac…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70634] TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionar…
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML…