Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1809
Esta semana
RSS
S Alto vulnerabilidad
09/06/2026
[CVE-2026-42570] Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't…
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in vers…
O Alto vulnerabilidad
09/06/2026
[CVE-2026-42764] Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dere…
Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service. If the address validation is disabled in the OpenSSL QUIC server implementation, an attac…
O Alto vulnerabilidad
09/06/2026
[CVE-2026-42765] Issue summary: When a partial-chain certificate verification is enabled together with OCSP response …
Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL dereference will happen if the verified chain does not have a self-signed trusted anchor, crashing the process. Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application. When performing OCSP response c…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-40376] Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privilege…
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-40404] Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
M Alto vulnerabilidad
09/06/2026
[CVE-2026-40409] Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
M Alto vulnerabilidad
09/06/2026
[CVE-2026-41092] Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges loca…
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/06/2026
[CVE-2026-41098] Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack …
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-41108] Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privile…
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
O Alto vulnerabilidad
09/06/2026
[CVE-2026-34183] Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with …
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the l…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-34335] Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele…
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-38615] DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-40371] Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) …
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-33828] Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges …
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
O Alto vulnerabilidad
09/06/2026
[CVE-2026-34180] Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content …
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes in length may cause a heap buffer over-read on 64-bit Unix and Unix-like platforms. Impact summary: The heap buffer over-read may crash the application (Denial of Service) or to load into the decoded ASN.1 object contents of memory beyond the end of the input buffer. More typic…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
O Alto vulnerabilidad
09/06/2026
[CVE-2026-34181] Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files th…
Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Based Message Authentication Code 1 (PBMAC1) integrity mechanism allowing a certificate and private key forgery. Impact Summary: An attacker impersonating a user can cause a service reading PKCS#12 files to accept forged certificates and private keys with a 1 in 256 probability. If…
O Crítico vulnerabilidad
09/06/2026
[CVE-2026-34182] Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input val…
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the cipher and tag length fields of AuthEnvelopedData containers, leading to various potential compromises. Impact Summary: Attackers making use of these vulnerabilities may achieve key-equivalent functionality for a given CMS recipient and/or bypass integrity validation for a given mess…
M Crítico vulnerabilidad
09/06/2026
[CVE-2026-26142] Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute c…
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-32193] Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Ku…
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-22926] Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.