Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Linux" — 1165 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1799
Esta semana
RSS
G Crítico vulnerabilidad
09/06/2026
[CVE-2026-11651] Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to exec…
Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11652] Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who …
Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11656] Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who con…
Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)
G Crítico vulnerabilidad
09/06/2026
[CVE-2026-11659] Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker t…
Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11643] Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execut…
Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11644] Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who co…
Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11646] Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker…
Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11649] Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a…
Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11650] Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute a…
Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/06/2026
[CVE-2026-11638] Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to pot…
Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11640] Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha…
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11642] Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who ha…
Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11629] Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potent…
Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11630] Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p…
Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
09/06/2026
[CVE-2026-11632] Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who co…
Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
L Alto vulnerabilidad
08/06/2026
[CVE-2026-46311] In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to…
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping Use drm_exec to take both locks i.e vm root bo and wptr_obj bo to access the mapping data properly. This fixes the security issue of unmap the wptr_obj while a queue creation is in progress and passing other bo at same address. (cherry picked from commit 1fc6c8ab45dbee096469c0…
L Alto vulnerabilidad
08/06/2026
[CVE-2026-46304] In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq…
In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the final controller reference through nvmet_cq_put(). If that triggers nvmet_ctrl_free(), the teardown path flushes ctrl->async_event_work on the same nvmet-wq. Call chain: nvmet_tcp_schedule_release_queue() …
L Alto vulnerabilidad
08/06/2026
[CVE-2026-46306] In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect …
In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT RECOMMENDED for PPPoE. In practice, pppd does not support negotiating PFC for PPPoE sessions, and the flow dissector driver has assumed an uncompressed frame until the blamed commit. During the review process o…
L Alto vulnerabilidad
08/06/2026
[CVE-2026-46307] In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access arra…
In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent reports: > The ath5k driver seems to do an array-index-out-of-bounds access as > shown by the UBSAN kernel message: > UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath5k/base.c:1741:20 > index 4 is out of range for type 'ieee80211_tx_rate [4]' > ... > Call Trace: >
L Alto vulnerabilidad
08/06/2026
[CVE-2026-46308] In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix use-aft…
In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix use-after-free in scpsys_get_bus_protection_legacy() In scpsys_get_bus_protection_legacy(), of_find_node_with_property() returns a device node with its reference count incremented. The function then calls of_node_put(node) before checking whether syscon_regmap_lookup_by_phandle() returns an error. If an e…