Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 min
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1740
Esta semana
RSS
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17675] Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h…
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17676] Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r…
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17666] Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a pr…
Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17652] Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had co…
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17655] Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed …
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17656] Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti…
Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17651] Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.7…
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-67403] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-67404] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-69942] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-69943] kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the pa…
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
M Crítico vulnerabilidad
29/07/2026
[CVE-2025-65340] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsrep…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67429] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.dow…
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67426] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the stand…
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback_url for an outbound POST with X-Internal-Key: $FLYTO_RUNNER_SECRET while bypassing target_allowed, allowing unauthenticated SSRF and runner secret …
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-14529] IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.…
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-16326] In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless…
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-41939] Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildF…
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Ar…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-51992] SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to ex…
SQL Injection vulnerability in ClickHouse Server Versions
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-54680] Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior t…
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd block using @t…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67191] Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that…
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP co…