Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106417] Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to poten…
Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106419] Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106401] Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to po…
Out of bounds write in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106382] Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to ex…
Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106372] Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to p…
Incorrect authorization in UI in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106375] Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to pote…
Incomplete cleanup in Dawn in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106358] Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to ex…
Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106329] Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attac…
Incorrect authorization in FileSystem in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106323] Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a …
Missing authorization in Chrome for iOS in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106298] Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote att…
Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106281] Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentia…
Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106241] Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a re…
Incorrect authorization in Search in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106234] Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveragi…
Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106239] Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote att…
Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106227] Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute …
Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106211] Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leverag…
Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106197] Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execu…
Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-102322] Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote at…
Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106102] Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.…
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. A…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105857] Payload is a free and open source headless content management system. In @payloadcms/plugin-form-bui…
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.