Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
07/08/2026
[CVE-2026-62296] HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in J…
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can t…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19177] Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a …
Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19169] Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.…
Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-57817] The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter …
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-20303] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are g…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-20273] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE So…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that ar…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-16793] An improper neutralization of special elements used in an operating system command vulnerability was…
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/08/2026
[CVE-2026-69185] Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.…
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.
M Alto vulnerabilidad
02/08/2026
[CVE-2025-71399] Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3,…
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extr…
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta en GitPython anterior a 3.1.50 permite inyección de código remoto
GitPython versiones anteriores a 3.1.50 no valida correctamente caracteres de salto de línea en el parámetro section de config_writer(), permitiendo a atacantes inyectar encabezados arbitrarios en .git/config. Los adversarios pueden manipular la sección [core] para dirigir hooksPath hacia directorios controlados, logrando ejecución de código remoto cuando se activan hooks de Git. Esta vulnerabilidad afecta principalmente a repositorios compartidos y entornos de integración continua en empresas de México y Latinoamérica.
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica de bypass de autorización en @better-auth/scim (CVE-2026-67330)
El plugin @better-auth/scim para better-auth en versiones 1.4.0-beta.27 a 1.6.21 y 1.7.0-beta.0 a 1.7.0-beta.9 contiene una falla de autorización que permite a atacantes reutilizar identificadores de proveedores SSO/SAML/OIDC existentes en la emisión de tokens SCIM, comprometiendo la identidad de usuarios y cuentas corporativas. Afecta principalmente sistemas de gestión de identidades y acceso (IAM) en empresas que implementan provisionamiento automático de usuarios.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad de denegación de servicio en FreeRDP anterior a versión 3.29.0
FreeRDP versiones anteriores a 3.29.0 contiene una vulnerabilidad de denegación de servicio (DoS) en el manejador del canal RDPEI que no valida la longitud máxima del cuerpo PDU antes de asignar memoria. Un cliente RDP malicioso puede enviar un mensaje RDPEI solo con encabezado y una longitud de cuerpo declarada grande, forzando asignación excesiva de memoria en el servidor. Empresas en LATAM que utilizan FreeRDP en infraestructuras de acceso remoto deben actualizar inmediatamente para evitar interrupciones de servicios altas.