Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
G Medio vulnerabilidad
28/07/2026
Chromium: CVE-2026-13030 Uninitialized Use in GPU
Microsoft publica advisory de seguridad: Chromium: CVE-2026-13030 Uninitialized Use in GPU.
M Medio vulnerabilidad
27/07/2026
CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting
Microsoft publica advisory de seguridad: CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting.
M Medio vulnerabilidad
27/07/2026
CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
Microsoft publica advisory de seguridad: CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist().
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-62835] Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over …
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-57106] Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privil…
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56163] Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unautho…
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56191] Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tamp…
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-56165] Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over…
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-56167] Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privi…
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-50517] Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over…
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
M Medio vulnerabilidad
23/07/2026
CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability. Tipo: Divulgación de Información.
M Alto vulnerabilidad
22/07/2026
CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50377 Windows Kernel Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Medio vulnerabilidad
22/07/2026
CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows
Microsoft publica advisory de seguridad: CVE-2026-57211 RabbitMQ: UNC SSRF affecting the management UI on Windows.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-50522] Vulnerabilidad explotada activamente en Microsoft SharePoint
CISA confirma explotación activa de una vulnerabilidad en Microsoft SharePoint. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-07-25.
M Medio vulnerabilidad
20/07/2026
CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
20/07/2026
CVE-2026-50659 .NET Spoofing Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-50659 .NET Spoofing Vulnerability. Tipo: Suplantación (Spoofing).
M Alto vulnerabilidad
20/07/2026
CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
M Alto vulnerabilidad
17/07/2026
[CVE-2026-56171] Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthori…
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-59117] Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code o…
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-58598] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.