Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68840] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68824] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-68825] Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges loc…
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67385] Use after free in SQL Server allows an authorized attacker to execute code over a network.
Use after free in SQL Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62813] Use after free in Active Directory Domain Services allows an authorized attacker to execute code ove…
Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62694] Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62697] Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges loc…
Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-56172] Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges lo…
Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-56177] Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-50349] Concurrent execution using shared resource with improper synchronization ('race condition') in Windo…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82061] A use-after-free security issue exists in the server's query execution memory tracking subsystem. An…
A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed heap memory through a sequence of standard database commands, leading to server process crash or potential memory corruption. No user interaction is required.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en PX4 Autopilot 1.17.0 y anteriores: use-after-free en módulo load_mon
PX4 Autopilot versiones hasta 1.17.0 contiene una vulnerabilidad use-after-free en el módulo load_mon que permite a atacantes ejecutar comandos maliciosos a través de shells PXH o MAVLink, causando corrupción de memoria. Esta falla afecta directamente sistemas de vehículos autónomos, drones industriales y equipos de defensa en operaciones altas en LATAM, siendo explotable sin autenticación en entornos accesibles.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85197] A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can ex…
A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read asynchronously. This can lead to memory corruption, potentially resulting in informat…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85048] Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who …
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85049] Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute …
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-33630] c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-…
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, o…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84347] Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execut…
Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84349] Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had …
Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84350] Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leverag…
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84123] Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was…
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.