Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10896] Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote att…
Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10899] Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker w…
Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10900] Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker…
Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10901] Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker…
Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10902] Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute…
Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10886] Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to po…
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10887] Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacke…
Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10888] Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the …
Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10890] Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local netw…
Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10891] Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to …
Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10893] Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to ex…
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10894] Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacke…
Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10882] Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execu…
Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10884] Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who h…
Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10885] Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote att…
Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
O Alto vulnerabilidad
04/06/2026
[CVE-2026-8829] HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS rou…
HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value contained its own key as an entity reference, a later call to grow_gap() reallocated…
L Alto vulnerabilidad
03/06/2026
[CVE-2026-46267] In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers an…
In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freeing context llc_shdlc_deinit() purges SHDLC skb queues and frees the llc_shdlc structure while its timers and state machine work may still be active. Timer callbacks can schedule sm_work, and sm_work accesses SHDLC state and the skb queues. If teardown happens in parallel with a …
L Alto vulnerabilidad
03/06/2026
[CVE-2026-46270] In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-…
In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `power_supply` handle, means that the `power_supply` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally dealloca…
L Alto vulnerabilidad
03/06/2026
[CVE-2026-46264] In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initializa…
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of devm_add_action_or_reset() failure the provided cleanup action will be run immediately on the not yet initialized kobject. This may lead to errors like: [ ] kobject: '(null)' (ff110001393608e0): is not initialized, yet kobject_put() is being called. [ ] WARNING: lib/kobject.c:734…
L Alto vulnerabilidad
03/06/2026
[CVE-2026-46246] In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix …
In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler Using the `devm_` variant for requesting IRQ _before_ the `devm_` variant for allocating/registering the `extcon` handle, means that the `extcon` handle will be deallocated/unregistered _before_ the interrupt handler (since `devm_` naturally deallocates in r…