Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76745] Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent a…
Memory corruption vulnerabilities exist in AOS-S that are reachable by an unauthenticated adjacent attacker. Successful exploitation could allow an attacker to execute arbitrary code.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76746] An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allo…
An unauthenticated buffer overflow vulnerability exists in AOS-S. Successful exploitation could allow an unauthenticated adjacent attacker to expose sensitive memory contents and cause a denial of service on the affected device.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106446] Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.…
Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars.compile() and Handlebars.precompile() accept pre-parsed AST objects while validating only selected PathExpression, NumberLiteral, and BooleanLiteral values. This issue bypasses the AST validation introduced in version 4.7.9 for CVE-2026-33937. An attacker who can supply an object inst…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-102159] An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access…
An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-101155] An authenticated remote attacker with specific permissions can read or write files on the platform f…
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository.
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-86360] Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Re…
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-55330] In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a …
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106414] Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remo…
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106417] Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to poten…
Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106419] Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106401] Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to po…
Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106382] Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to ex…
Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106372] Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to p…
Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106375] Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to pote…
Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106358] Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to ex…
Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106329] Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attac…
Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106323] Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a …
Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106298] Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote att…
Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106281] Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentia…
Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-106241] Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a re…
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)