Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
17/06/2026
[CVE-2025-71322] PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowin…
PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypass security checks. Malicious actors can craft pickle payloads using pty.spawn to achieve arbitrary code execution when files are processed by PickleScan.
G Alto vulnerabilidad
17/06/2026
[CVE-2026-12438] Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed …
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
O Alto vulnerabilidad
16/06/2026
[CVE-2026-53853] OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that …
OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux and macOS systems. Attackers can bypass configured argPattern restrictions by directly invoking allowlisted executables with unrestricted arguments, potentially enabling unauthorized file access, network access, or…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-12214] A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the …
A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBindingComposeW of the component Nucleus Engine Monitoring Logic. Performing a manipulation of the argument NetworkAddr results in protection mechanism failure. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47135] vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-…
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox code can obtain real cross-realm symbols, write them to host objects, and control host-side behavior — …
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47139] vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding pub…
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes underscored internal HTTP builtins such as _http_client and _http_server. These are not blocked when th…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47209] vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in b…
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inherits from the proxy via Object.create), the property assignment should create an own property on the …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
11/06/2026
[CVE-2026-12031] Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a …
Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A Alto vulnerabilidad
11/06/2026
[CVE-2025-24284] This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed i…
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.
M Alto vulnerabilidad
11/06/2026
[CVE-2026-48546] KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute ar…
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull request modifying messages.cjs to import arbitrary Node.js modules, bypassing sandbox restrictions an…
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48575] Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi…
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48568] Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi…
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-48570] Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi…
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-47656] Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a secur…
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45656] Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feat…
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45588] Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi…
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11248] Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote…
Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
04/06/2026
[CVE-2026-11170] Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed …
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)