Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Google" — 1248 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84333] Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attack…
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84334] Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed …
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84335] Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacke…
Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84347] Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execut…
Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84349] Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had …
Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84350] Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leverag…
Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84351] Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attack…
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84324] Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute…
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84326] Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to ex…
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84325] Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote a…
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-75865] The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode pl…
The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attacker…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82808] A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impac…
A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand ab…
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82638] jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthe…
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de SSRF en Budibase backend-core permite eludir restricciones de red
Budibase backend-core omite el rango 100.64.0.0/10 de su lista negra predeterminada de SSRF, permitiendo que usuarios autenticados con permisos de Builder ejecuten consultas REST datasource contra redes internas. Este rango es alta en infraestructuras cloud compartidas (AWS, Google Cloud) donde se asignan direcciones privadas. La vulnerabilidad afecta principalmente a deployments autohospedados sin configuración personalizada de listas negras.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82072] Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execut…
Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-19889] GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t…
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting in the disclosure of Google Vertex AI or AWS Bed…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79290] Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute …
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79292] Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who…
Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79275] Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute…
Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-79282] Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)