Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50257] A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client…
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to the X server to set up a fence and await that fence, then a second X connection destroys the fence, causing the use-after-free. This may be used to crash the server, or for privileg…
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21035] Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to ac…
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21037] Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to acc…
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
G Alto vulnerabilidad
05/06/2026
Vulnerabilidad alta en Android OS (CVE-2026-21029) con CVSS 7.8 afecta dispositivos en LATAM
Google Android ha publicado un advisory sobre una vulnerabilidad de severidad alta (CVSS 7.8) en Android OS que impacta millones de dispositivos móviles en México y Latinoamérica, representando más del 80% del parque móvil regional. Esta falla de seguridad requiere actualización inmediata en todos los equipos corporativos y personales para prevenir explotación remota.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21030] Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers…
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21031] Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch a…
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21032] Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant pr…
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21033] Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant …
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11332] A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency speci…
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galax…
H Alto vulnerabilidad
05/06/2026
[CVE-2026-21837] HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Man…
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-50593] Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actio…
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-41567] Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to…
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operation…
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11303] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11304] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potent…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11305] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11306] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11307] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
Vulnerabilidad alta en Android OS (CVE-2026-11297) - CVSS 7.7
Google publica alerta sobre vulnerabilidad de severidad alta en Android OS que afecta más del 80% de dispositivos móviles en México y Latinoamérica. La falla permite comprometer la seguridad de terminales corporativas y personales. Se recomienda aplicar el parche de seguridad de inmediato en todos los dispositivos del inventario.
G Alto vulnerabilidad
05/06/2026
Escalación de privilegios alta en Android OS (CVE-2026-11295) - CVSS 8.8
Vulnerabilidad de escalación de privilegios en Android OS con puntuación CVSS 8.8 afecta dispositivos móviles en México y Latinoamérica, representando riesgo significativo para más del 80% del parque móvil regional. Un atacante podría obtener permisos elevados sin autenticación explícita del usuario. La actualización de seguridad está disponible mediante el canal oficial de Google.
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11296] Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remot…
Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)