Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
Buscando: "X" — 10687 resultados ✕ Limpiar búsqueda
14,391
Total alertas
3276
Críticas
10807
Altas
8
Ransomware
1041
Esta semana
RSS
N Alto vulnerabilidad
22/07/2026
[CVE-2026-65016] n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Ent…
n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role (unlike the token-exchange identity path, which rejects it). An SSO-authenticated user whose instance-role claim resolves to gl…
N Crítico vulnerabilidad
22/07/2026
[CVE-2026-65590] n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and …
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. This issue only affects…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-44189] A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider…
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. Th…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-44190] A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vuln…
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or exec…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-14551] The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.…
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restric…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63047] Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Bo…
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-3821] Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. …
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12968] The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not r…
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-15802] The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient …
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution …
C Alto vulnerabilidad
22/07/2026
[CVE-2026-16232] Vulnerabilidad explotada activamente en Check Point SmartConsole
CISA confirma explotación activa de una vulnerabilidad en Check Point SmartConsole. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-25.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-50522] Vulnerabilidad explotada activamente en Microsoft SharePoint
CISA confirma explotación activa de una vulnerabilidad en Microsoft SharePoint. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-25.
N Crítico vulnerabilidad
21/07/2026
[CVE-2026-56817] Netty is a network application framework for development of protocol servers and clients. In version…
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a `DOCTYPE` declaration to an `AsyncXMLInputFactory` instantiated with no security configuration, leaving DTD and entity h…
G Crítico vulnerabilidad
21/07/2026
[CVE-2026-16424] Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker …
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
21/07/2026
[CVE-2026-16416] Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to …
Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16418] Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to ex…
Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Crítico vulnerabilidad
21/07/2026
[CVE-2026-16419] Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a …
Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16420] Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to exe…
Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16421] Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote a…
Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16422] Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7…
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16423] Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convince…
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)