Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-11043] Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacke…
Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-11037] Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to p…
Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-11021] Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53…
Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-11029] Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149…
Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-11009] Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker t…
Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-11002] Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had…
Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10990] Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had com…
Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10983] Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a…
Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10971] Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.78…
Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10972] Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker t…
Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10974] Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed …
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10966] Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote atta…
Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10931] Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to po…
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10886] Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to po…
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
04/06/2026
[CVE-2026-10881] Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attac…
Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
04/06/2026
[CVE-2024-27892] Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when…
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
M Crítico vulnerabilidad
04/06/2026
[CVE-2024-27890] Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when…
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
M Crítico vulnerabilidad
04/06/2026
[CVE-2025-71316] SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unico…
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.
N Crítico vulnerabilidad
04/06/2026
[CVE-2026-48040] The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivi…
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses for cryptographic operations versions prior to 0.0.22.Final provide a fallback path for direct ByteBufs that do not expose their memory address through `hasMemoryAddress()`. This fallback occurs when …
M Crítico vulnerabilidad
04/06/2026
[CVE-2026-10880] OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username fi…
OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password.