Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61938] Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61934] Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges loc…
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61927] Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges loc…
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61929] Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61361] Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61357] Use after free in Application Information Services allows an authorized attacker to elevate privileg…
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61348] Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele…
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61349] Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges lo…
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61346] Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locall…
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59122] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-59125] Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate p…
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-53415] Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve …
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-50060] A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed…
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-50061] A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Ed…
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-43631] llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab…
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerability by sending requests to affected endpoints while the server transitions to sleep mode, causing concurrent worker thre…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-43632] llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-ser…
llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that bypass the task queue and access ctx_server.vocab directly on HTTP worker threads. Attackers can exploit a time-of-check-time-of-use race condition where the main th…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-1289] A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulne…
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19176] Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had co…
Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-19170] Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacke…
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19172] Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had c…
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)