Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87470] Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a rem…
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87474] Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to pote…
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87464] Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute…
Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87448] Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to exec…
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87455] Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentia…
Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87438] Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote …
Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-53939] OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In ve…
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-53581] OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core …
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape th…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-85982] The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to imprope…
The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could th…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-84869] A condition in the ScreenConnect client may allow files to be transferred and executed through an ac…
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-75746] ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQ…
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-48273] ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('E…
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-19232] Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result i…
Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-82004] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-76200] Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-76201] Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused…
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-66302] External control of file name or path in Skype for Business allows an unauthorized attacker to execu…
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-58822] In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting…
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-49921] In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This c…
In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-83941] Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network…
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.