Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1741
Esta semana
RSS
A Crítico vulnerabilidad
12/06/2026
[CVE-2026-49875] Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory w…
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fix this issue.
A Crítico vulnerabilidad
12/06/2026
[CVE-2026-50627] The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of inc…
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
A Crítico vulnerabilidad
12/06/2026
[CVE-2026-50628] A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP addres…
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
A Alto vulnerabilidad
10/06/2026
[CVE-2026-50223] Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low…
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.
A Alto vulnerabilidad
10/06/2026
[CVE-2026-47342] A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o…
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.
A Alto vulnerabilidad
10/06/2026
[CVE-2026-25700] Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affect…
Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixe…
A Alto vulnerabilidad
08/06/2026
[CVE-2026-48913] Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already ex…
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Alto vulnerabilidad
08/06/2026
[CVE-2026-44185] Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker contr…
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A Alto vulnerabilidad
08/06/2026
[CVE-2026-44186] Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in …
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A Crítico vulnerabilidad
08/06/2026
[CVE-2026-44631] Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configur…
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A Crítico vulnerabilidad
08/06/2026
[CVE-2026-42535] A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to d…
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A Alto vulnerabilidad
08/06/2026
[CVE-2026-42536] Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and…
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A Alto vulnerabilidad
08/06/2026
[CVE-2026-34355] A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an …
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A Alto vulnerabilidad
08/06/2026
[CVE-2026-34356] Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and Pr…
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A Crítico vulnerabilidad
08/06/2026
[CVE-2026-29167] Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration Thi…
Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Alto vulnerabilidad
08/06/2026
[CVE-2026-47430] ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WK…
## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser can fire any pending Cordova callback in the host app by posting a message whose `id` field is a guessable or enumerated cal…
A Crítico vulnerabilidad
04/06/2026
[CVE-2026-50076] Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK…
Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present readResolve/readExternal hooks via crafted Fory serialized data. Users are recommended to upgrade to version 1.1.0 or later, which fixes thi…
A Crítico vulnerabilidad
03/06/2026
[CVE-2026-47065] ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Pro…
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which perform…
A Alto vulnerabilidad KEV
16/04/2026
Vulnerabilidad crítica en Apache ActiveMQ bajo explotación activa
Apache ha confirmado explotación activa de CVE-2026-34197 en Apache ActiveMQ. CISA ha establecido el 30 de abril de 2026 como fecha límite para remediar la vulnerabilidad en sistemas federales estadounidenses. Aunque no se ha detectado uso en campañas de ransomware conocidas, organizaciones en México y LATAM deben considerar este plazo como referencia de urgencia máxima dado el estado de explotación activa.