Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106412] Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker w…
Race condition in Core in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106207] Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute ar…
Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47497] NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing compon…
NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-92369] TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in…
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of th…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100713] Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH ke…
Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile() is done only at check time; the live filesystem path is re-resolved as root at write time (file_put_contents with FILE_APP…
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad de race condition en paquete npm OpenClaw anterior a 2026.7.1
El paquete OpenClaw (npm) antes de la versión 2026.7.1 contiene una vulnerabilidad de time-of-check time-of-use (TOCTOU) en operaciones del sistema de archivos de OpenShell. Los atacantes pueden explotar condiciones de carrera en operaciones de eliminación, creación y renombre de directorios para eludir controles de sandbox y acceder a rutas no autorizadas. Esta vulnerabilidad afecta a aplicaciones Node.js que dependen de OpenClaw para aislar operaciones del sistema de archivos.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91813] A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replace…
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77242] MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira).…
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf checks a hostname's resolved addresses, but Requests and urllib3 resolve the hostname again when connecting. A caller can use a short-lived DNS answer that is public during validation and private during connection, preserving unauthenticated access to internal…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-77633] Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg…
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditional storage charge outside the same quota-enforcing transaction. An authenticated user with Files.Write permission can issue concurrent upload-session requests that …
M Alto vulnerabilidad
21/09/2026
[CVE-2026-55567] BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Window…
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory with a Windows junction and use a native symlink to redirect the elevated deletion to an attacker-selected file. The arbitrary privileged file deletion can be combi…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-45720] Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.…
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can each observe the assertion as unused and obtain authentication as the victim before …
M Alto vulnerabilidad
17/09/2026
[CVE-2026-25278] Memory Corruption when processing I2C transfer requests due to a race condition between memory alloc…
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91743] Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had com…
Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91748] Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote atta…
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91712] Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote atta…
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-40058] CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. …
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. An update is available immediately for versions 7.34 and above, 7.32 LTS, and …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82429] Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker di…
Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid of 0. Both syscalls re-resolve the path at the time of the call, after FTS has classified the entry, and the trees being walked are owned and writable by the untr…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82430] Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes …
Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wrote into that same directory. The file is opened without `O_NOFOLLOW` and without re-verifying its owner, so between the ownership change and the read…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-68488] A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk c…
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88924] A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownersh…
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an ar…