Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49193] Overly permissive configuration settings on cloud storage containers expose active telemetry informa…
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
A Alto vulnerabilidad
04/06/2026
[CVE-2026-49187] The hard-coded APK resource files never expire, and the shared scepter leads to information leaks an…
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-36611] Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer w…
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST requests without SOAPAction header on UPnP port 1900, exposing internal memory to unauthenticated adjacent network attackers.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-41032] It is possible for an unauthenticated adjacent attacker to download log files of the controller, whi…
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
L Crítico vulnerabilidad
02/06/2026
[CVE-2026-32625] LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and in…
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-co…
M Alto vulnerabilidad
02/06/2026
[CVE-2026-45553] NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reSt…
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application passes attacker-controlled content to ui.restructured_text(), an attacker can use standard Docutils directives (include, csv-table with :file:, raw with :file:) to read local files readable…