Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 30 min
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
M Alto vulnerabilidad
09/06/2026
[CVE-2026-40409] Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
M Alto vulnerabilidad
09/06/2026
[CVE-2026-41092] Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges loca…
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-41098] Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack …
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-41108] Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile…
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
O Alto vulnerabilidad
09/06/2026
[CVE-2026-34183] Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with …
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the l…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-34335] Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele…
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-40371] Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) …
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/06/2026
[CVE-2026-33828] Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges …
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
O Alto vulnerabilidad
09/06/2026
[CVE-2026-34180] Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content …
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer. More typic…
O Alto vulnerabilidad
09/06/2026
[CVE-2026-34181] Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files th…
Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery. Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability. If…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-32193] Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Ku…
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-22926] Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-24180] NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffe…
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-24181] NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index …
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
N Alto vulnerabilidad
09/06/2026
[CVE-2026-0419] Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit releas…
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure cont…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
N Alto vulnerabilidad
09/06/2026
[CVE-2026-0411] An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could al…
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NETGEAR models are affected by this vulnerability. Orbi WiFi Systems without satellite devices are not impacted by this issue.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-49948] Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability …
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validating the caller's role. Any authenticated user holding a distributed API key can redirect all LLM and emb…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-24064] Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerab…
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime entitlements that permit dynamic library injection. A local attacker can set the DYLD_INSERT_LIBRARIES environment variable to inject an attacker-controlled dynamic library into the trusted client process…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-24065] Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerab…
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the client process identifier (PID) to verify code-signing identity. Because process identifiers can be reused, a local attacker can exploit a race condition between the time a connection request is made and th…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-10727] An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions…
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root