Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 26 min
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87526] Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker levera…
Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87527] Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execut…
Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87512] Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87504] Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging …
Use after free in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87494] Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote att…
Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87500] Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote…
Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87488] Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attac…
Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87492] Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacke…
Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87470] Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a rem…
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87474] Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to pote…
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87464] Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute…
Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87448] Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to exec…
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87455] Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentia…
Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87438] Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote …
Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-53939] OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In ve…
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-53581] OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core …
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape th…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-85982] The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to imprope…
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could th…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-84869] A condition in the ScreenConnect client may allow files to be transferred and executed through an ac…
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-75746] ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQ…
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-48273] ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('E…
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.