Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
CVE-2026-104704: Vulnerabilidad alta en hMailServer 6.0.0-6.3.5 por falta de validación TLS en SMTP
hMailServer versiones 6.0.0 a 6.3.5 no implementa correctamente la validación DANE/TLSA para entregas SMTP salientes, permitiendo degradación a conexiones sin TLS cuando los registros DNSSEC no contienen registros DANE-EE. Esto expone las comunicaciones de correo en tránsito a empresas mexicanas y latinoamericanas que usan este servidor de correo, comprometiendo la confidencialidad de mensajes según RFC 7672.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107232] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authoriza…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103098] Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent…
Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key
M Alto vulnerabilidad
01/10/2026
[CVE-2026-67105] HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could al…
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-82826] Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sens…
Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials and sensitive data in transit. This issue affects Hitachi Coding Software Suite: through 3.3.0.