Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
27/08/2026
[CVE-2026-76640] Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT serv…
Unitree G1 EDU firmware through 1.5.2 contains multiple chained vulnerabilities in the BLE GATT server and WiFi provisioning stack that allow unauthenticated proximate attackers to achieve root code execution without pairing or credentials by exploiting an unquoted heredoc variable in the WiFi provisioning script and a buffer overflow in the SSID chunk accumulator. Attackers can send crafted BLE w…
M Alto vulnerabilidad
27/08/2026
Desbordamiento de búfer en pruebas NASL permite acceso completo al sistema (CVE-2026-81625)
Atacantes remotos con privilegios de usuario pueden ejecutar pruebas de vulnerabilidad NASL maliciosas o comprometidas para provocar un desbordamiento de búfer en la pila y obtener acceso total al sistema afectado. Esta vulnerabilidad de severidad alta (CVSS 8.8) afecta múltiples plataformas de escaneo de vulnerabilidades ampliamente utilizadas en centros de datos e infraestructuras altas de LATAM.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58096] LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the…
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79240] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79188] Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to po…
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79189] Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to po…
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79138] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79131] Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ex…
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79127] Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to ex…
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79043] Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to po…
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79048] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79019] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78952] Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remo…
Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-68513] OpenEXR is the reference implementation and specification for the EXR image format, widely used in t…
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels. When separate_channels=false, PyOpenEXR maps each physical channel name through channelN…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-68515] OpenEXR is the reference implementation and specification for the EXR image format, widely used in t…
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-75770] Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit…
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-75749] Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbit…
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-71564] Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbi…
Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-71382] Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbit…
Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-59982] OpenEXR is the reference implementation and specification for the EXR image format, widely used in t…
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row …