Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Crítico vulnerabilidad
06/08/2026
Vulnerabilidad crítica en autenticación condicional (CVE-2025-15039) permite bypass de desafíos de autenticación
Un fallo en los scripts de Autenticación Condicional (Adaptive Authentication) permite a atacantes eludir desafíos de autenticación intermedios en configuraciones de múltiples pasos. La vulnerabilidad afecta sistemas de control de acceso empresariales en toda Latinoamérica, poniendo en riesgo aplicaciones críticas que dependen de autenticación multifactor. Con puntuación CVSS 9.4, este vector compromete la integridad de flujos de autenticación en plataformas de identidad y control de acceso.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-70608] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenHandler with no user interaction because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction. Apps that e…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-70601] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-18015] Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote…
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17899] Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attac…
Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17865] Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remo…
Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17856] Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a rem…
Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17710] Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot…
Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17695] Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remot…
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17669] Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowe…
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17676] Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r…
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17677] Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a r…
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/07/2026
[CVE-2026-67427] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workf…
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment variable without an allowlist or capability policy check, allowing a workflow parameter to bypass the default capability policy denylist for env.get and env.load_dotenv and exfiltrate secrets through allowed modules. This issue…
A Alto vulnerabilidad
27/07/2026
[CVE-2026-28912] A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8,…
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-44090] An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and…
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/07/2026
[CVE-2025-50324] An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary co…
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-50327] An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privile…
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism
M Crítico vulnerabilidad
22/07/2026
[CVE-2025-50329] An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate…
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-50330] An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate pr…
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-44089] An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloadin…
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.