Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
N Alto vulnerabilidad
09/06/2026
[CVE-2026-0419] Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit releas…
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows users connected to the local WiFi Networks to execute operating system commands. NETGEAR JR6150 has reached End-of-Support phase as of 2018 , and no further security updates are planned. NETGEAR strongly recommends replacing these devices with newer NETGEAR models to ensure cont…
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11689] Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remo…
Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11682] Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a re…
Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11676] Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 1…
Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11660] Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 …
Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
N Alto vulnerabilidad
08/06/2026
[CVE-2026-49234] When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/or…
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks.
A Alto vulnerabilidad
08/06/2026
[CVE-2026-47430] ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WK…
## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser can fire any pending Cordova callback in the host app by posting a message whose `id` field is a guessable or enumerated cal…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/06/2026
[CVE-2026-11460] A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function…
A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation causes improper validation of specified type of input. It is possible to initiate the attack remotely. The exploit has been published and may be used. The maintainer was notified on Aug 2025 and a disclosure deadline was set for 90 days. The maintainer acknowledged but postponed …
M Alto vulnerabilidad
05/06/2026
[CVE-2026-45291] Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in v…
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a bug in Network to close the parent netty channel, rendering it inoperable. All consumers of the library should upgrade to at least ve…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-36501] An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to ca…
An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11272] Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.78…
Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11255] Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.782…
Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11239] Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote …
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11241] Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a…
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11242] Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowe…
Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
04/06/2026
[CVE-2026-11235] Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a rem…
Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-11237] Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed …
Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-11202] Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowe…
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-11158] Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.…
Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentially perform a sandbox escape via a crafted AppleScript command. (Chromium security severity: Medium)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-11149] Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 all…
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)