Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
866
Esta semana
RSS
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78911] Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who…
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78913] Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to po…
Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78899] Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar…
Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78901] Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar…
Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78905] Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potenti…
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78891] Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execu…
Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta en NVIDIA OpenShell permite inyección de comandos del sistema operativo
NVIDIA OpenShell en todas las plataformas contiene una vulnerabilidad (CVSS 8.8) que permite a un gateway malicioso ejecutar inyección de comandos del SO, potencialmente resultando en ejecución de código arbitrario, manipulación de datos y divulgación de información. Esta vulnerabilidad afecta directamente a infraestructuras de computación en la nube y servidores empresariales en LATAM que utilizan OpenShell como componente de virtualización o contenedores.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de traversal de ruta en NVIDIA OpenShell Sandbox para Linux (CVE-2026-65092)
NVIDIA OpenShell Sandbox para Linux contiene una vulnerabilidad que permite a atacantes eludir la política de seguridad de red L7 REST mediante traversal de ruta, facilitando acceso no autorizado a información sensible y manipulación de datos. Esta falla afecta infraestructuras de contenedorización y edge computing en datacenters de LATAM que dependen de OpenShell para aislamiento de cargas de trabajo.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta en NVIDIA NemoClaw para Linux permite inyección de comandos del SO
NVIDIA NemoClaw para Linux contiene una vulnerabilidad en el componente Telegram bridge que permite a atacantes inyectar comandos del sistema operativo. La explotación exitosa podría resultar en ejecución de código arbitrario, escalada de privilegios, divulgación de información y manipulación de datos en servidores altas de empresas en LATAM.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta en NVIDIA NemoClaw para Linux permite ejecución de código remoto
NVIDIA NemoClaw para Linux contiene una vulnerabilidad en sus scripts de instalación que permite descargar código sin validar su integridad. Un atacante puede explotar esto para ejecutar código arbitrario, escalar privilegios, acceder a información sensible o modificar datos. Afecta especialmente a centros de datos y empresas que utilizan herramientas de IA basadas en NVIDIA en infraestructura on-premise.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65098] NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an at…
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de inyección de comandos en NVIDIA NemoClaw para Linux (CVE-2026-65099)
NVIDIA NemoClaw para Linux contiene una vulnerabilidad en su interfaz de línea de comandos que permite inyección de comandos del sistema operativo. Un atacante podría explotar esta falla para ejecutar código arbitrario, modificar datos, acceder a información confidencial o provocar denegación de servicio. Afecta principalmente a servidores y estaciones de trabajo con GPU NVIDIA en entornos de desarrollo e IA.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65105] NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote att…
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65084] NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker coul…
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65089] NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an …
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65090] NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacke…
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65081] NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker co…
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-65082] NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker …
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-74932] The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it…
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached pages with references to a server they control and have arbitrary JavaScript run for every subsequent visitor.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-68513] OpenEXR is the reference implementation and specification for the EXR image format, widely used in t…
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between literal and prefixed RGB channels. When separate_channels=false, PyOpenEXR maps each physical channel name through channelN…