Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1784
Esta semana
RSS
M Alto vulnerabilidad
03/06/2026
[CVE-2026-36574] A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escal…
A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.
M Crítico vulnerabilidad
03/06/2026
[CVE-2026-36576] An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up …
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
C Medio vulnerabilidad
03/06/2026
Cisco Webex Meetings Cross-Site Scripting Vulnerability
Cisco PSIRT publica advisory de seguridad: Cisco Webex Meetings Cross-Site Scripting Vulnerability. Tipo: Cross-Site Scripting (XSS). Producto afectado: Cisco Webex. Security Impact Rating: Medium.
C Crítico vulnerabilidad
03/06/2026
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
Cisco PSIRT publica advisory de seguridad: Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability. Tipo: Vulnerabilidad de seguridad. Producto afectado: Cisco. Security Impact Rating: Critical.
C Medio vulnerabilidad
03/06/2026
Cisco Finesse Remote File Inclusion Vulnerability
Cisco PSIRT publica advisory de seguridad: Cisco Finesse Remote File Inclusion Vulnerability. Tipo: Vulnerabilidad de seguridad. Producto afectado: Cisco. Security Impact Rating: Medium.
H Crítico vulnerabilidad
03/06/2026
[CVE-2026-5241] A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows…
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when lo…
M Alto vulnerabilidad
03/06/2026
[CVE-2026-37460] Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.…
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
S Alto vulnerabilidad
03/06/2026
[CVE-2022-49042] An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in …
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
S Alto vulnerabilidad
03/06/2026
[CVE-2022-49036] An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration i…
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35084] A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain…
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35085] A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to ga…
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35079] The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files…
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35080] The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local f…
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35081] The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processe…
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35082] The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files…
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35083] A remote attacker with user privileges can exploit a stack buffer overflow to gain full system acces…
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
M Crítico vulnerabilidad
03/06/2026
[CVE-2026-35075] An unauthenticated remote attacker can recover a default, hard coded password from a firmware image …
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35076] The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local fi…
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35077] The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local …
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35078] The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local file…
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.