Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101156] A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege adminis…
A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensit…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-101157] A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacen…
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82162] Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed En…
Dell Command | Configure (DCC), versions prior to 5.2.3.35, contain an Improper Handling of Mixed Encoding vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-83550] A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints …
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from …
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-86360] Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Re…
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-86361] Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Criti…
Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-86362] Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A …
Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-63697] Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerabi…
Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-71168] Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Re…
Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Remote execution.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-55330] In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a …
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-56906] In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could le…
In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106441] Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, …
Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.6 and 1.4.0.dev9, Hydra passes Python logging configuration to logging.config.dictConfig() without applying Hydra's target policy to handler class values or formatter, filter, handler, queue, and listener factories. An attacker who controls Hydra logging configuration can therefore select an importable class or facto…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106442] Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.…
Hydra is a framework for elegantly configuring complex applications. From 1.3.4 until 1.3.6 and 1.4.0.dev9, the instantiate() target blacklist introduced for CVE-2026-68508 incompletely checks the effective callable selected by the target field. Execution wrappers such as timeit.timeit, executable deserialization through pickle.loads, aliases, callable-returning helpers, generic dispatch, and defe…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106443] WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in we…
WeasyPrint helps web developers to create PDF documents. Prior to 70.0, the image-loading path in weasyprint/images.py passes fetched image bytes from HTML img URLs, CSS image values, SVG image references, and data URIs to Pillow's generic image dispatcher without excluding EPS or PostScript formats. On hosts with Ghostscript installed, Pillow EpsImagePlugin invokes the interpreter for attacker-co…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106423] Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute…
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106426] Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potenti…
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-106440] Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.…
Hydra is a framework for elegantly configuring complex applications. From 1.2.0 until 1.3.0 and 1.4.0.dev10, the hydra-optuna-sweeper package accepts a configuration-controlled dotted path in hydra.sweeper.custom_search_space, resolves it with hydra.utils.get_method(), and later invokes the returned callable in the Hydra controller process. Because get_method() is a trusted-input lookup helper and…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106414] Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remo…
Improper input validation in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106417] Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to poten…
Integer overflow in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-106419] Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)