Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-48582] Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileg…
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
19/06/2026
[CVE-2026-47645] Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows …
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-45480] Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privile…
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
19/06/2026
[CVE-2026-32208] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft En…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
M Crítico vulnerabilidad
19/06/2026
[CVE-2025-62821] Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDat…
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call.
M Crítico vulnerabilidad
18/06/2026
[CVE-2026-54130] Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disc…
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
18/06/2026
[CVE-2026-47633] Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experience…
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/06/2026
[CVE-2026-47647] Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privilege…
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
18/06/2026
[CVE-2026-32174] Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges ove…
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
16/06/2026
[CVE-2026-50656] Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Micros…
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
M Alto vulnerabilidad
09/06/2026
[CVE-2026-50512] Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker t…
Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-50511] Improper link resolution before file access ('link following') in Microsoft PC Manager allows an aut…
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-49161] Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security f…
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48574] Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48575] Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi…
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48576] No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feat…
No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48578] Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges l…
Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48583] Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-49160] Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a n…
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48565] Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privilege…
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.