Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-64904] Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor…
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-61932] Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an …
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-15572] A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Al…
A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, fails to re-validate the mapper type during a client update if the mapper's configuration remains unchanged. An attacker with client registration privileges can exploit this by first registering an all…
M Alto vulnerabilidad
04/08/2026
Vulnerabilidad alta de confusión de tipos en Microsoft Edge permite ejecución remota de código
Se ha identificado una vulnerabilidad de confusión de tipos (type confusion) en Microsoft Edge basado en Chromium que permite a atacantes ejecutar código arbitrario de forma remota con CVSS 7.4. Esta vulnerabilidad afecta potencialmente a millones de usuarios corporativos en México y Latinoamérica que utilizan este navegador en entornos empresariales, comprometiendo la seguridad de estaciones de trabajo y datos sensibles.
G Alto vulnerabilidad
30/07/2026
[CVE-2026-17989] Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar…
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17948] Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a use…
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17725] Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar…
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16420] Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to exe…
Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
14/07/2026
[CVE-2026-15776] Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacke…
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
14/07/2026
[CVE-2026-58541] Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized at…
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-57108] Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized at…
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55024] Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un…
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55025] Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un…
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55022] Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthor…
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50686] Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized …
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50491] Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privilege…
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50421] Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences …
Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50390] Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized…
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
13/07/2026
[CVE-2026-55771] CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained …
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead to incorrect equality comparisons. The EntityIdentifier.equals() method has inverted logic for null and self-reference checks, returning true for null comparisons and f…
M Alto vulnerabilidad
13/07/2026
[CVE-2026-55772] CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained …
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Record-to-Entity type confusion across the Java-Rust FFI boundary. CedarJava sends authorization requests to the Rust cedar-policy evaluator as JSON. The JSON protoc…