Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
M Crítico vulnerabilidad
15/07/2026
[CVE-2026-14960] Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\…
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes without authorization checks. A local attacker can abuse this functionality to manipulate hardware re…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-20150] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS en…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20150 are related to improper access control that are grouped und…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-47164] Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO log…
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an attacker-controlled IdP identity asserting a victim email address to bind to and authenticate as that account. This issue…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47301] Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate …
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-58617] Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate …
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-57088] Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevat…
Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50465] Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering …
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50423] Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locall…
Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50373] Improper access control in Microsoft Windows Search Component allows an authorized attacker to eleva…
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50335] Improper access control in Windows Operating Systems allows an authorized attacker to elevate privil…
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55014] Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate priv…
Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50342] Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate priv…
Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50351] Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to …
Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50311] Improper access control in Windows Server allows an authorized attacker to elevate privileges locall…
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50325] Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall…
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50297] Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall…
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-49805] Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall…
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15677] A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown funct…
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
13/07/2026
[CVE-2026-57855] Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/b…
Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, rename, createfolder) without performing any ACL or role check. Any authenticated user, regardless of role, can perform all bucket operations on any named bucket, including bucke…
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-51538] EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability i…
EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there…