Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
G Crítico vulnerabilidad
29/09/2026
[CVE-2026-95284] Vulnerabilidad Android en Android OS - CVSS 9.6
Vulnerabilidad de seguridad en Android (Android OS): Desbordamiento de Buffer. CVSS: 9.6. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95277] Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potenti…
Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95281] Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote atta…
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95283] Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attac…
Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-84436] IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI f…
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-77177] Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other prod…
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
M Crítico vulnerabilidad
29/09/2026
[CVE-2023-54400] Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that al…
Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the Microsoft SQL Server backend to extract, disclose, and modify database contents, with…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-82973] Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox befo…
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100818] Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in F…
Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100819] Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was f…
Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100811] Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed…
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100800] Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was…
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100804] Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was f…
Sandbox escape due to use-after-free in the Preferences: Backend component. This vulnerability was fixed in Firefox 157.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100786] Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Fire…
Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100778] Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed…
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100770] Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was…
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-100762] Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was…
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de autenticación en Hitachi Energy RTU500 permite carga de firmware no autorizada
Se ha identificado una vulnerabilidad de omisión de autenticación (CVE-2026-8065, CVSS 9.1) en el endpoint de actualización de firmware de Hitachi Energy RTU500 que permite a atacantes no autenticados cargar firmware malicioso mediante solicitudes POST modificadas. La explotación exitosa podría comprometer la funcionalidad operativa, integridad y disponibilidad del dispositivo, afectando principalmente infraestructuras críticas de energía, agua y telecomunicaciones en LATAM que dependen de estos controladores RTU.
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de traversal de directorios en Hitachi Energy RTU500 permite escritura de archivos arbitrarios
Una vulnerabilidad de traversal de directorios en la funcionalidad de carga de archivos del Hitachi Energy RTU500 permite a atacantes no autenticados escribir o sobrescribir archivos arbitrarios en el sistema de ficheros del dispositivo. La explotación exitosa podría resultar en modificación no autorizada de datos críticos de control o interrupción de operaciones en plantas de generación, subestaciones y sistemas de distribución de energía comúnmente desplegados en infraestructura LATAM.
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de inyección de código en GEOVIA Geospatial Data Manager (CVSS 9.9)
Una vulnerabilidad de inyección de código afecta GEOVIA Geospatial Data Manager en las versiones 3DEXPERIENCE R2024x hasta R2026x, permitiendo a atacantes ejecutar código arbitrario en el servidor. Empresas en México y LATAM que utilizan esta plataforma para gestión de datos geoespaciales enfrentan riesgo crítico de compromiso total de infraestructura si no aplican parches inmediatamente.