Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106409] Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 a…
Incorrect reference resolution in WebAppInstalls in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106308] Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 all…
Incorrect reference resolution in Autofill in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106274] Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed …
Incorrect reference resolution in Browser in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106279] Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowe…
Incorrect reference resolution in Passwords in Google Chrome on on iOS prior to 155.0.8059.39 allowed a local attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95334] Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remot…
Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77605] Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run …
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appended, and the user invokes Run by system on the text file on Windows 10 or Windows 11, Notepad++ can…
M Crítico vulnerabilidad
17/09/2026
[CVE-2026-92951] vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlis…
vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that contains an allowlisted package substring, causing vm2 to load and execute unauthorized host packages in the host context.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91727] Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allow…
Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87613] Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remot…
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87618] Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allo…
Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-87547] Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remot…
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81383] Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker …
Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78985] Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remot…
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-67602] phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows una…
phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without including the searched column, enabling an entry written during an app_id lookup to satisfy a subsequent app_code lookup, allowing attackers to use…
M Crítico vulnerabilidad
20/08/2026
[CVE-2026-65816] Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat…
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
20/08/2026
[CVE-2026-13097] A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos pri…
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized a…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-29036] cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability …
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted JSON Pointer escape sequences (~0 or ~1) in patch paths. Attackers can submit malicious RFC 6902 JSON Patch input to app…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-62685] File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing…
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=true and CreateUserDir=true, but the many-to-one normalization can collapse usernames such as team/one, team one, and team-one to the same home directo…
O Alto vulnerabilidad
13/07/2026
[CVE-2026-62190] OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper…
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval binding and perform unauthorized operations when the affected feature is enabled.
D Alto vulnerabilidad
26/06/2026
[CVE-2026-13372] Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote …
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.