Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84352] Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attac…
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84353] Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a …
Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84333] Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attack…
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84347] Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execut…
Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84349] Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had …
Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84350] Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leverag…
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84324] Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute…
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84123] Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was…
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84119] Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed …
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84121] Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in…
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-42007] An attacker that has valid credentials can use a Sieve script with the editheader extension to trigg…
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the c…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81934] Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handl…
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58093] The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After rea…
The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58090] The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messag…
The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58091] The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If lock…
The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did not handle this possibility. On a system with a multiple audio devices, an unprivileged local user can exploit this use-a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79290] Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute …
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79275] Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute…
Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79282] Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79266] Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leverag…
Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79257] Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute…
Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)