Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1783
Esta semana
RSS
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11635] Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke…
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11636] Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote atta…
Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11637] Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to…
Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
09/06/2026
[CVE-2026-11638] Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to pot…
Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11639] Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attac…
Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11640] Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha…
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11641] Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote att…
Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11642] Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha…
Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11629] Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potent…
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11630] Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p…
Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11631] Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker…
Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11632] Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who co…
Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11633] Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacke…
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
G Crítico vulnerabilidad
09/06/2026
[CVE-2026-11634] Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attac…
Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
08/06/2026
[CVE-2026-46484] Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Head…
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/06/2026
[CVE-2026-49141] WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine…
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modif…
M Alto vulnerabilidad
08/06/2026
[CVE-2026-40519] Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticate…
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a malicious payload in the dns_provider_credentials field. The user-controlled dns…
M Alto vulnerabilidad
08/06/2026
[CVE-2026-11582] A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is…
A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
M Crítico vulnerabilidad
08/06/2026
[CVE-2026-52778] YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability e…
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. This implementation is inherently flawed: it is vulnerable to Regu…
S Alto vulnerabilidad
08/06/2026
[CVE-2026-46490] samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template su…
samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., ) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new elements inside the signed assertion. The IdP then signs the tampe…