Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Microsoft" — 1744 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1015
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 8 horas
CVE-2026-69566 Windows NTFS Remote Code Execution Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-69566 Windows NTFS Remote Code Execution Vulnerability. Tipo: Ejecución Remota de Código (RCE).
M Crítico vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-94510] Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attack…
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-96207] Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to eleva…
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-88131] Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute …
Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-84058] IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Micr…
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM Guardium Collector may cause a denial of service or potentially execute arbitrary code on the Collector appliance.
M Alto vulnerabilidad Nuevo
Hace 19 horas
[CVE-2026-107782] System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc …
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Microsoft-signed host like rundll32.exe, connect to SiSvcApiPort, and call PhSvcApiCreateService to execute code as SYSTEM.
M Medio vulnerabilidad
Hace 1 día
CVE-2026-58528 Windows USB Audio Class Driver Information Disclosure Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-58528 Windows USB Audio Class Driver Information Disclosure Vulnerability. Tipo: Divulgación de Información.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Medio vulnerabilidad
Hace 1 día
Chromium: CVE-2025-11215 Off by one error in V8
Microsoft publica advisory de seguridad: Chromium: CVE-2025-11215 Off by one error in V8.
G Medio vulnerabilidad
Hace 1 día
Chromium: CVE-2025-11219 Use after free in V8
Microsoft publica advisory de seguridad: Chromium: CVE-2025-11219 Use after free in V8.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107219] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier validation. OpenFile reaches agileDecrypt, which passes the unbounded spinCount to convertPasswdToKey before password verification. When a crafted OLE encrypt…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107217] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing na…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107214] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or ag…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107215] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107216] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-flight and iteration controls. ANCHORARRAY calls CalcCellValue instead of cellResolver, so each recursive hop receives a new calcContext and loses cycle st…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107212] Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 t…
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Medio vulnerabilidad
Hace 2 días
Chromium: CVE-2025-0611 Object corruption in V8
Microsoft publica advisory de seguridad: Chromium: CVE-2025-0611 Object corruption in V8.
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-101207] Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains a…
Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105791] Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. P…
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attack…
M Alto vulnerabilidad
Hace 3 días
CVE-2026-72999 Windows USB Hub Driver Elevation of Privilege Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-72999 Windows USB Hub Driver Elevation of Privilege Vulnerability. Tipo: Elevación de Privilegios (EoP).
G Medio vulnerabilidad
Hace 6 días
Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE
Microsoft publica advisory de seguridad: Chromium: CVE-2025-10502 Heap buffer overflow in ANGLE.