Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1075
Esta semana
RSS
M Crítico vulnerabilidad
11/08/2026
CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61920 Windows DNS Server Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Medio vulnerabilidad
11/08/2026
CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-61918 Windows Remote Desktop Client Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-16053] Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to A…
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-4757] A VAPIX API parameter had improper input validation which could allow code execution and potentially…
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19516] A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re…
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and r…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-13716] Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authent…
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
? Crítico alerta
11/08/2026
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Three Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-20349, CVE-2026-68820, CVE-2026-72898.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-19425] Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability…
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-19424] Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability.…
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
M Medio vulnerabilidad
11/08/2026
CVE-2026-68146 ftrace: Add global mutex to serialize trace_parser access
Microsoft publica advisory de seguridad: CVE-2026-68146 ftrace: Add global mutex to serialize trace_parser access.
M Medio vulnerabilidad
11/08/2026
CVE-2026-68181 mei: bus: access mei_device under device_lock on cleanup
Microsoft publica advisory de seguridad: CVE-2026-68181 mei: bus: access mei_device under device_lock on cleanup.
M Medio vulnerabilidad
11/08/2026
CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate
Microsoft publica advisory de seguridad: CVE-2026-68388 smb/client: handle overlapping allocated ranges in fallocate.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-66763] SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated w…
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected inform…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58243] SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality…
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44764] Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence…
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44765] Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence…
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, in…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-58230] SAP Approuter does not sufficiently validate certain token content under specific configurations. An…
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality …
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-34265] SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors i…
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-44758] SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to subm…
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44763] SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient …
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the i…