Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95365] Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to pot…
Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95306] Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute ar…
Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95286] Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to exec…
Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102556] A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection…
A flaw was found in libsoup. When handling an incoming WebSocket Pong frame, SoupWebsocketConnection emitted the ::pong signal with a GByteArray pointer even though the signal is declared to pass a GBytes. Applications connecting a handler that follows the documented GBytes API can trigger heap corruption or a crash upon receiving a crafted Pong.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97737] In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lo…
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96883] pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2…
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions. To remediate this issue, users should upgrade …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91741] Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to …
Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91731] Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to e…
Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91709] Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to…
Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45762] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's IP defragmentation tracker lookup did not verify that an existing tracker used the same IP address family as the packet being processed. Under crafted fragmented IPv4/IPv6 traffic, an IPv6 fragment could be associated with an IPv4 defr…
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87636] Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potential…
Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87612] Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute ar…
Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
08/09/2026
[CVE-2026-80161] Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulne…
Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77888] Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unaut…
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77889] Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unaut…
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77890] Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unaut…
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77499] Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unaut…
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77494] Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unaut…
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70584] Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an au…
Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69717] Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privi…
Untrusted pointer dereference in Windows Group Policy allows an authorized attacker to elevate privileges over a network.