Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15976] SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace reposit…
SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-12118] IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to …
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-57859] e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization h…
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The e_array::unserialize() function in e107_handlers/core_functions.php performs only a prefix check for the string 'array' before passing the st…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-1360] The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versio…
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject ar…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-58163] Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or cras…
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-14974] IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute a…
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
M Crítico vulnerabilidad
28/07/2026
[CVE-2026-14512] IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe…
IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/07/2026
[CVE-2026-66713] Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache So…
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered …
M Crítico vulnerabilidad
28/07/2026
[CVE-2026-11756] A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE pla…
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
J Alto vulnerabilidad
27/07/2026
[CVE-2026-65617] A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user t…
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-63077] In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible …
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
M Alto vulnerabilidad
26/07/2026
[CVE-2026-15962] The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all v…
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. The additional presence of a POP chain allows attackers to change user passwords and potentially take over a…
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-50517] Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over…
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65497] Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
Administrator PHP Object Injection in Complianz
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65493] Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
Subscriber PHP Object Injection in Dokan Pro

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-59544] Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
Unauthenticated PHP Object Injection in Thrive Quiz Builder
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-16723] A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerabi…
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
O Crítico vulnerabilidad
22/07/2026
[CVE-2026-60369] Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen…
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security…
O Crítico vulnerabilidad
22/07/2026
[CVE-2026-60372] Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen…
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result i…
O Alto vulnerabilidad
22/07/2026
[CVE-2026-60373] Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (componen…
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in…