Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,138
Total alertas
3230
Críticas
10635
Altas
8
Ransomware
1060
Esta semana
RSS
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58283] Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all…
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57975] Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all…
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57977] Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ed…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57981] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57983] Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass …
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57984] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57985] Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exec…
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57986] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28744] Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer to…
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-56645] Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe…
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57974] Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to…
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27771] Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package s…
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27775] Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receiv…
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27779] Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting publ…
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-27780] Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive…
Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28699] Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed…
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28737] Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsReq…
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28740] Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source obj…
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-26231] Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to …
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-26232] Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single…
Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.