Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica en GitLab EE permite acceso a credenciales sensibles (CVE-2026-87719)
GitLab Enterprise Edition presenta una falla de seguridad en versiones 18.3 a 19.3.1 que permite a usuarios autenticados con acceso a Duo Chat obtener configuraciones de Advanced Search y credenciales sensibles mediante argumentos GraphQL especialmente diseñados. La vulnerabilidad afecta principalmente a empresas LATAM que utilizan GitLab EE para almacenar código crítico y secretos de aplicaciones. Con puntuación CVSS 9.9, esta falla requiere atención inmediata en infraestructuras de DevOps.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-62103] Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Unauthenticated PHP Object Injection in Everest Forms
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-62105] Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62107] Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
Unauthenticated PHP Object Injection in Masteriyo - LMS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-73699] FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated atta…
FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required named-key array to disable class instantiation. Attackers with database write access can inject a serialized gadget chain …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81784] Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
Unauthenticated PHP Object Injection in Wise Chat
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82925] The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized…
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such insta…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87874] A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although…
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a n…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87930] MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, …
MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt application state or achieve code execution if gadget classes exist.
M Alto vulnerabilidad
09/09/2026
[CVE-2024-58381] PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processin…
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81385] Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to e…
Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77484] Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a…
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69694] Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authoriz…
Deserialization of untrusted data in Windows IP Address Management (IPAM) Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-65772] Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute…
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-47297] Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over…
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-12744] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-12745] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-12648] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-12650] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-12651] A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a …
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.