Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95283] Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attac…
Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-84436] IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI f…
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-77177] Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other prod…
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
M Crítico vulnerabilidad
29/09/2026
[CVE-2023-54400] Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that al…
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with…
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-82973] Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox befo…
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100818] Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in F…
Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100819] Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was f…
Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100811] Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed…
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100800] Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was…
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100804] Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was f…
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100786] Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Fire…
Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100778] Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed…
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100770] Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was…
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100762] Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was…
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de autenticación en Hitachi Energy RTU500 permite carga de firmware no autorizada
Se ha identificado una vulnerabilidad de omisión de autenticación (CVE-2026-8065, CVSS 9.1) en el endpoint de actualización de firmware de Hitachi Energy RTU500 que permite a atacantes no autenticados cargar firmware malicioso mediante solicitudes POST modificadas. La explotación exitosa podría comprometer la funcionalidad operativa, integridad y disponibilidad del dispositivo, afectando principalmente infraestructuras críticas de energía, agua y telecomunicaciones en LATAM que dependen de estos controladores RTU.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de traversal de directorios en Hitachi Energy RTU500 permite escritura de archivos arbitrarios
Una vulnerabilidad de traversal de directorios en la funcionalidad de carga de archivos del Hitachi Energy RTU500 permite a atacantes no autenticados escribir o sobrescribir archivos arbitrarios en el sistema de ficheros del dispositivo. La explotación exitosa podría resultar en modificación no autorizada de datos críticos de control o interrupción de operaciones en plantas de generación, subestaciones y sistemas de distribución de energía comúnmente desplegados en infraestructura LATAM.
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de inyección de código en GEOVIA Geospatial Data Manager (CVSS 9.9)
Una vulnerabilidad de inyección de código afecta GEOVIA Geospatial Data Manager en las versiones 3DEXPERIENCE R2024x hasta R2026x, permitiendo a atacantes ejecutar código arbitrario en el servidor. Empresas en México y LATAM que utilizan esta plataforma para gestión de datos geoespaciales enfrentan riesgo crítico de compromiso total de infraestructura si no aplican parches inmediatamente.
? Crítico alerta
29/09/2026
CISA Adds One Known Exploited Vulnerability to Catalog
CISA emite alerta de seguridad: CISA Adds One Known Exploited Vulnerability to Catalog. CVEs relacionados: CVE-2026-86950.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-102240] A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the…
A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not res…
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-101354] A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the fun…
A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab…