Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1785
Esta semana
RSS
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21035] Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to ac…
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21037] Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to acc…
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21030] Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers…
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21031] Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch a…
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21032] Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant pr…
Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
S Alto vulnerabilidad
05/06/2026
[CVE-2026-21033] Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant …
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11332] A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency speci…
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galax…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
H Alto vulnerabilidad
05/06/2026
[CVE-2026-21837] HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Man…
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-50593] Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actio…
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-41567] Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to…
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operation…
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11303] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11304] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potent…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11305] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11306] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11307] Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execut…
Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11296] Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remot…
Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11301] Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote…
Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11279] Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to …
Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11272] Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.78…
Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
05/06/2026
[CVE-2026-11265] Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote at…
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)