Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 31 min
14,165
Total alertas
3233
Críticas
10659
Altas
8
Ransomware
1019
Esta semana
RSS
H Alto vulnerabilidad
03/07/2026
[CVE-2026-11352] An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote de…
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-11564] libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if …
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
H Alto vulnerabilidad
03/07/2026
[CVE-2026-11586] By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound …
By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.
H Crítico vulnerabilidad
03/07/2026
[CVE-2026-11856] Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** auth…
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-9725] The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Ar…
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-13040] The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cro…
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injecte…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14352] The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up …
The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The three intended access controls all fail: valid nonces are freely minted by unauthentica…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14327] The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to…
The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires an attacker to first obtain a valid nonce and secure nonce via the publ…
M Crítico vulnerabilidad
03/07/2026
[CVE-2026-13768] Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user t…
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific connected device and may allow the malicious user to pivot to other devices on the…
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13383] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authe…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13384] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authen…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13053] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13054] A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged a…
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13079] A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows …
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-45499] Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileg…
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-54998] Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privil…
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-57100] Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an au…
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
02/07/2026
[CVE-2026-41106] Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker …
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
L Alto vulnerabilidad
02/07/2026
[CVE-2026-50721] Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the …
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to …
L Alto vulnerabilidad
02/07/2026
[CVE-2026-50722] Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verif…
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a …