Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 56 min
Buscando: "Linux" — 1165 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
M Alto vulnerabilidad
12/06/2026
[CVE-2025-7003] Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF…
Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.56.
M Alto vulnerabilidad
12/06/2026
[CVE-2025-7004] Heap buffer out-of-bounds write vulnerability in Avast Antivirus when scanning a malformed Windows P…
Heap buffer out-of-bounds write vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25040308. The affected scanning…
M Alto vulnerabilidad
12/06/2026
[CVE-2025-7008] Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE…
Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file with .NET metadata may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021310. The…
M Alto vulnerabilidad
12/06/2026
[CVE-2025-7009] Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE…
Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25021310. The affected scanning …
L Alto vulnerabilidad
12/06/2026
[CVE-2026-3840] A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a c…
A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version string. The `_get_versioned_path()` method in `kedro/io/core.py` directly interpolates user-supplied version strings into filesystem paths without sanitization. This enables an attacker to escape the intended versioned dataset directory and access files outside the expected path. The …
P Alto vulnerabilidad
11/06/2026
[CVE-2026-45174] Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potent…
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19
G Crítico vulnerabilidad
11/06/2026
[CVE-2026-12027] Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote a…
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12034] Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior …
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12016] Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote a…
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12019] Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowe…
Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12008] Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attac…
Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12012] Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileg…
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12014] Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local net…
Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
P Alto vulnerabilidad
11/06/2026
[CVE-2026-45175] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within…
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bull…
P Alto vulnerabilidad
11/06/2026
[CVE-2026-45176] Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within…
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actio…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
P Alto vulnerabilidad
10/06/2026
[CVE-2026-0271] A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux…
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS.
P Alto vulnerabilidad
10/06/2026
[CVE-2026-0270] A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux …
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
M Alto vulnerabilidad
10/06/2026
[CVE-2026-46529] Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A si…
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PD…
G Alto vulnerabilidad
10/06/2026
[CVE-2026-1220] Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit …
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
P Crítico vulnerabilidad
10/06/2026
CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
Palo Alto Networks PSIRT publica advisory de seguridad: CVE-2026-0268 Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux (Severity: MEDIUM). Tipo: Vulnerabilidad de seguridad. Producto afectado: Prisma Access.