Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 16 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12020] Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker…
Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12022] Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who …
Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12023] Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who …
Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12008] Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attac…
Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12009] Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7…
Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12012] Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileg…
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12014] Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local net…
Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
P Alto vulnerabilidad
11/06/2026
[CVE-2026-45175] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within…
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bull…
P Alto vulnerabilidad
11/06/2026
[CVE-2026-45176] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within…
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actio…
A Alto vulnerabilidad
11/06/2026
[CVE-2025-46315] A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 2…
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.
A Alto vulnerabilidad
11/06/2026
[CVE-2025-24284] This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i…
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.
A Alto vulnerabilidad
11/06/2026
[CVE-2025-31272] The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may …
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.
A Alto vulnerabilidad
10/06/2026
[CVE-2022-26758] A malicious application may cause unexpected changes in memory shared between processes. A memory co…
A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4.
G Alto vulnerabilidad
10/06/2026
[CVE-2026-1220] Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit …
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
A Alto vulnerabilidad
09/06/2026
[CVE-2026-47906] Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party…
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Alto vulnerabilidad
09/06/2026
[CVE-2026-47907] Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerabili…
Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
A Alto vulnerabilidad
09/06/2026
[CVE-2026-47908] Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vul…
Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
A Alto vulnerabilidad
09/06/2026
[CVE-2026-48293] InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerabil…
InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
A Alto vulnerabilidad
09/06/2026
[CVE-2026-34706] InCopy versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that c…
InCopy versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
A Alto vulnerabilidad
09/06/2026
[CVE-2026-34707] InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability …
InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.