Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3572 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1272
Esta semana
RSS
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79047] Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging…
Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79026] Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker lever…
Use after free in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79019] Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote …
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79012] Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote at…
Use after free in Safebrowsing in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78989] Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote a…
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78985] Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remot…
Incorrect reference resolution in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78964] Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker t…
Use after free in Sync in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78951] Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to…
Use after free in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78945] Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging…
Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78948] Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execut…
Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78935] Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a …
Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78937] Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote atta…
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78939] Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who h…
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
25/08/2026
[CVE-2026-78909] Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging…
Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78900] Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker…
Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-78904] Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potenti…
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de escape de sandbox en NVIDIA OpenShell para Linux (CVE-2026-65093)
NVIDIA OpenShell para Linux contiene una vulnerabilidad que permite a atacantes escapar del sandbox e ejecutar código arbitrario con privilegios elevados. El impacto incluye ejecución remota de código, escalada de privilegios, manipulación de datos y divulgación de información sensible. Empresas en LATAM que utilicen OpenShell en entornos containerizados o de virtualización deben considerar este vector de alto riesgo.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65083] NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attack…
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-45018] Chainlit is a Python framework for building production-ready conversational AI applications. From 2.…
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string. The validate_mcp_command() function in backend/chai…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79787] Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configurat…
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.