Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
G Alto vulnerabilidad
30/07/2026
[CVE-2026-17993] Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perfo…
Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)
G Alto vulnerabilidad
30/07/2026
[CVE-2026-17979] Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co…
Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17855] Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had co…
Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17709] Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had c…
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17711] Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had c…
Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17712] Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arb…
Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17654] Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform O…
Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/07/2026
[CVE-2026-62432] The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without …
The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-62430] Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs t…
Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest chosen index, and one of the usages of the index didn't take the necessary locking to avoid concurrent changes. As a result, a guest could change the index after it being checked, causing a subsequent out-of-bound read access to the contents of an array.
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-64720] A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPa…
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-43805] A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPa…
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-43755] A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 1…
A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-43728] This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6.…
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-43693] A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15…
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-28982] A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, m…
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
A Alto vulnerabilidad
27/07/2026
[CVE-2026-28926] A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15…
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate privileges.
S Alto vulnerabilidad
20/07/2026
[CVE-2026-63756] SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc …
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.
L Alto vulnerabilidad
19/07/2026
[CVE-2026-53400] In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter registra…
In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter registration race Adapters can be looked up based on their id using i2c_get_adapter() which takes a reference to the embedded struct device. Make sure that the adapter (including its struct device) has been initialised before adding it to the IDR to avoid accessing uninitialised data which could, for exam…
M Alto vulnerabilidad
17/07/2026
[CVE-2026-51082] A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE…
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different us…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-58598] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.