Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 4 min
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
996
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107914] Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration ex…
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107908] A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB b…
A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then co…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-7826] A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/ser…
A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/serializer_io.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or disclose heap memory by supplying a crafted RDB stream whose sub-buffer length field exceeds the re…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-7827] A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializ…
A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with a…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-5759] A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph …
A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process …
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-94510] Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attack…
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-96207] Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to eleva…
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-83943] Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorize…
Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-83947] Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a n…
Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-88131] Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute …
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-77900] Missing authentication for critical function in Azure App Service allows an unauthorized attacker to…
Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-69435] Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a …
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107728] Strawberry GraphQL is a library for creating GraphQL APIs. From 0.217.0 until 0.326.1, PermissionExt…
Strawberry GraphQL is a library for creating GraphQL APIs. From 0.217.0 until 0.326.1, PermissionExtension.resolve() on a synchronous field resolver evaluates the result of has_permission() for truthiness. When a custom permission declares has_permission() as a normal function but returns an awaitable, supports_sync does not classify it as asynchronous, the awaitable is not awaited, and its inhere…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-89091] A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection insta…
A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink di…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-84249] IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary man…
IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-84875] IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-84035] IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-84057] IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary com…
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-84058] IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Micr…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-84198] IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.