Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1815
Esta semana
RSS
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-75874] Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 …
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-74938] Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Fire…
Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-47686] vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbo…
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process from an embedder-exposed host function that throws an error with that object as its cause and then exe…
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt: ejecución de plugins sin restricciones de sandbox
Las versiones de openssl_encrypt anteriores a 1.4.0 no aplican restricciones de aislamiento en la ejecución de plugins, permitiendo a atacantes acceder sin límites al sistema de archivos, red, subprocesos y módulos Python. Esta vulnerabilidad afecta directamente a servidores en LATAM que procesan encriptación y ejecutan plugins dinámicos, comprometiendo la confidencialidad e integridad de datos sensibles.
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt permite evasión de sandbox y ejecución de comandos
Versiones anteriores a 1.4.0 de openssl_encrypt contienen una vulnerabilidad de evasión de sandbox (CVSS 9.8) en el analizador AST DangerousPatternVisitor que no detecta técnicas de traversal de atributos dunder (__class__, __bases__, __subclasses__(), __globals__). Atacantes pueden ejecutar comandos arbitrarios desde código de plugins, comprometiendo servidores en México y Latinoamérica que dependan de esta librería para cifrado y procesamiento de datos sensibles.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-74790] Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change…
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica en autenticación condicional (CVE-2025-15039) permite bypass de desafíos de autenticación
Un fallo en los scripts de Autenticación Condicional (Adaptive Authentication) permite a atacantes eludir desafíos de autenticación intermedios en configuraciones de múltiples pasos. La vulnerabilidad afecta sistemas de control de acceso empresariales en toda Latinoamérica, poniendo en riesgo aplicaciones críticas que dependen de autenticación multifactor. Con puntuación CVSS 9.4, este vector compromete la integridad de flujos de autenticación en plataformas de identidad y control de acceso.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-18015] Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote…
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17865] Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remo…
Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17856] Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a rem…
Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17710] Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot…
Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17695] Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot…
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17669] Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe…
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17676] Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r…
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
22/07/2026
[CVE-2025-50329] An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate…
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-47392] PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers…
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `builtins` module, from which `__import__` can be extracted via `vars()` and runtime string construct…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16406] Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thund…
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16407] Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153…
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16390] Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153,…
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16394] Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Th…
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.