Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Crítico vulnerabilidad
17/08/2026
Vulnerabilidad crítica en openssl_encrypt permite evasión de sandbox y ejecución de comandos
Versiones anteriores a 1.4.0 de openssl_encrypt contienen una vulnerabilidad de evasión de sandbox (CVSS 9.8) en el analizador AST DangerousPatternVisitor que no detecta técnicas de traversal de atributos dunder (__class__, __bases__, __subclasses__(), __globals__). Atacantes pueden ejecutar comandos arbitrarios desde código de plugins, comprometiendo servidores en México y Latinoamérica que dependan de esta librería para cifrado y procesamiento de datos sensibles.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-74790] Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change…
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica en autenticación condicional (CVE-2025-15039) permite bypass de desafíos de autenticación
Un fallo en los scripts de Autenticación Condicional (Adaptive Authentication) permite a atacantes eludir desafíos de autenticación intermedios en configuraciones de múltiples pasos. La vulnerabilidad afecta sistemas de control de acceso empresariales en toda Latinoamérica, poniendo en riesgo aplicaciones críticas que dependen de autenticación multifactor. Con puntuación CVSS 9.4, este vector compromete la integridad de flujos de autenticación en plataformas de identidad y control de acceso.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-18015] Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote…
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17865] Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remo…
Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17856] Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a rem…
Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17710] Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot…
Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17695] Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot…
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17669] Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe…
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17676] Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r…
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
22/07/2026
[CVE-2025-50329] An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate…
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-47392] PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to vers…
PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `builtins` module, from which `__import__` can be extracted via `vars()` and runtime string construct…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16406] Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thund…
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16407] Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153…
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16390] Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153,…
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16394] Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Th…
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16380] Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thund…
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16382] Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153…
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16383] Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Fir…
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-16388] Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thu…
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.