Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1783
Esta semana
RSS
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58282] Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor…
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27779] Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting publ…
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28699] Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed…
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-26247] Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during a…
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-26292] Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror op…
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27660] Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the requ…
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-22555] Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first…
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24451] Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public t…
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24690] Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull reque…
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25712] Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for…
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-20706] Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope c…
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-20896] Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by defaul…
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55112] A malicious actor with access to the network and low privileges and under certain conditions could e…
A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55114] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-55116] A malicious actor with access to the network and under certain network configurations could exploit …
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55118] A malicious actor with access to the network,low privileges and under certain conditions could explo…
A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-55119] A malicious actor with access to the network and low privileges could exploit an Improper Access Con…
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54407] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
U Alto vulnerabilidad
02/07/2026
[CVE-2026-54408] A malicious actor with access to the network could exploit an Improper Access Control vulnerability …
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
U Crítico vulnerabilidad
02/07/2026
[CVE-2026-54400] A malicious actor with access to the network and high privileges could exploit an Improper Access Co…
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.