Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 3226 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1782
Esta semana
RSS
G Alto vulnerabilidad
04/06/2026
Escalación de Privilegios alta en Android NFC – CVE-2026-11108 (CVSS 8.8)
Vulnerabilidad de escalación de privilegios en el módulo NFC de Android afecta más del 80% de dispositivos móviles en México y Latinoamérica. Un atacante puede ejecutar código con permisos elevados sin interacción del usuario mediante comunicación NFC cercana. Se recomienda actualización inmediata en todos los dispositivos corporativos y personales.
G Alto vulnerabilidad
04/06/2026
Vulnerabilidad alta en Android OS (CVE-2026-11085) - CVSS 8.8
Google ha publicado un parche de seguridad para una vulnerabilidad alta en Android OS con puntuación CVSS de 8.8. Esta falla afecta a más del 80% de dispositivos móviles en México y Latinoamérica, exponiendo equipos corporativos y personales a compromisos de seguridad. La actualización está disponible en todos los canales de distribución de Android.
G Alto vulnerabilidad
04/06/2026
Escalación de privilegios alta en Android OS (CVE-2026-11035) — CVSS 7.3
Se ha identificado una vulnerabilidad de escalación de privilegios en Android OS con puntuación CVSS 7.3 que afecta dispositivos en México y Latinoamérica, donde Android representa más del 80% del mercado móvil. Un atacante podría obtener permisos elevados comprometiendo la integridad de datos corporativos y personales. La actualización de seguridad está disponible a través del menú de Ajustes del sistema.
G Alto vulnerabilidad
04/06/2026
Vulnerabilidad alta Use-After-Free en Android OS (CVE-2026-11012) - CVSS 8.3
Android OS contiene una vulnerabilidad Use-After-Free (UAF) de severidad alta (CVSS 8.3) que afecta más del 80% de dispositivos móviles en México y Latinoamérica. Un atacante podría ejecutar código arbitrario con privilegios elevados mediante una aplicación maliciosa o contenido web malformado. La vulnerabilidad impacta directamente operaciones corporativas y acceso a datos sensibles en dispositivos de trabajadores remotos.
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10973] Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak …
Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10976] Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtai…
Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
04/06/2026
Vulnerabilidad alta Use-After-Free en Android OS (CVE-2026-10967) - CVSS 8.3
Se ha identificado una vulnerabilidad de tipo Use-After-Free (UAF) en Android OS con puntuación CVSS 8.3, afectando más del 80% del mercado móvil en México y Latinoamérica. Un atacante podría ejecutar código arbitrario mediante la explotación de esta falla en la gestión de memoria del sistema operativo. La actualización de seguridad está disponible inmediatamente en todos los dispositivos Android.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
04/06/2026
[CVE-2026-10960] Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who ha…
Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
04/06/2026
Vulnerabilidad alta Use-After-Free en Android OS (CVE-2026-10953) – CVSS 8.3
Se ha identificado una vulnerabilidad de tipo Use-After-Free (UAF) en Android OS con puntuación CVSS 8.3, afectando potencialmente a más del 80% de dispositivos móviles en México y Latinoamérica. Esta falla permite a atacantes ejecutar código arbitrario con privilegios elevados comprometiendo datos sensibles y control del dispositivo. El parche de seguridad está disponible a través de Google Play System Update.
G Alto vulnerabilidad
04/06/2026
Vulnerabilidad alta Use-After-Free en Android OS (CVE-2026-10923) — CVSS 8.8
Se ha identificado una vulnerabilidad de Use-After-Free (UAF) en Android OS con puntuación CVSS 8.8, afectando más del 80% de dispositivos móviles en México y Latinoamérica. Esta falla permite la ejecución de código con privilegios elevados comprometiendo la confidencialidad, integridad y disponibilidad de datos empresariales. La explotación puede realizarse sin interacción del usuario en escenarios de ataque dirigido.
M Alto vulnerabilidad
04/06/2026
[CVE-2025-8873] On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause…
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the …
M Alto vulnerabilidad
04/06/2026
[CVE-2026-10872] A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserve…
A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. This project is superseded by FreshTomato.
M Alto vulnerabilidad
04/06/2026
[CVE-2026-10873] A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of t…
A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
M Alto vulnerabilidad
04/06/2026
[CVE-2026-10871] A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function s…
A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This project is superseded by FreshTomato.
M Alto vulnerabilidad
04/06/2026
[CVE-2026-10870] A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file …
A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This project is superseded by FreshTomato.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/06/2026
[CVE-2026-41236] Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following fl…
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning code appends public keys to `~/.ssh/authorized_keys` under a customer-controlled home directory without verifying that the target path is not a symbolic link. If an attacker controls a shell-enabled custo…
M Alto vulnerabilidad
04/06/2026
[CVE-2026-41234] Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add`…
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does not sanitize newline characters in TXT record content. An authenticated customer with DNS editing enabled can inject newlines into TXT record values, which break out of the record line in the generated BIND zone file. This enables injection of arbitrary BIND directives (`$INCLUDE`…
O Alto vulnerabilidad
04/06/2026
[CVE-2026-10796] nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied …
nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the available versions from the mirror's index.tab and use the selected version, without sanitization, to build download URLs and shell/awk commands. Two sinks are affected by the same untrusted input: nvm_download() built a…
M Alto vulnerabilidad
04/06/2026
[CVE-2025-67448] The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The …
The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user input in SMS messages before storing and displaying them. An attacker can send an SMS containing a malicious XSS payload, which will be executed in the context of the victim's browser when the message is viewed.
R Alto vulnerabilidad
04/06/2026
[CVE-2026-49941] Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called …
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the addresses did not look like netmasks or network ranges, then they were assumed to single IP addresses and passed back to itself as a 32-bit or 128-bit netmask. If the argument was not a well-formed IP address, then this would lead to indefinite recursio…