Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 32 min
Buscando: "Apple" — 566 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
A Alto vulnerabilidad
27/07/2026
[CVE-2026-28912] A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8,…
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-28926] A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15…
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate privileges.
A Crítico vulnerabilidad
27/07/2026
[CVE-2026-28928] A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.…
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-28931] A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and i…
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-28896] The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, …
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexpected system termination or read kernel memory.
A Medio vulnerabilidad
27/07/2026
iOS 26.6 (23G71)
Apple lanza actualización de seguridad para iOS versión 26.6. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Medio vulnerabilidad
27/07/2026
iPadOS 26.6 (23G71)
Apple lanza actualización de seguridad para iPadOS versión 26.6. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Medio vulnerabilidad
27/07/2026
macOS 26.6 (25G72)
Apple lanza actualización de seguridad para macOS versión 26.6. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Medio vulnerabilidad
27/07/2026
tvOS 26.6 (23L773)
Apple lanza actualización de seguridad para tvOS versión 26.6. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Medio vulnerabilidad
27/07/2026
visionOS 26.6 (23O770)
Apple lanza actualización de seguridad para visionOS versión 26.6. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
A Medio vulnerabilidad
27/07/2026
watchOS 26.6 (23U67)
Apple lanza actualización de seguridad para watchOS versión 26.6. Esta actualización incluye parches de seguridad importantes. Se recomienda actualizar de inmediato en todos los dispositivos Apple.
G Crítico vulnerabilidad
20/07/2026
[CVE-2026-15899] Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote att…
Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
L Alto vulnerabilidad
17/07/2026
[CVE-2026-13445] IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile …
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (c…
L Crítico vulnerabilidad
17/07/2026
[CVE-2026-13446] IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptog…
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
L Crítico vulnerabilidad
17/07/2026
[CVE-2026-8505] IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic…
IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the ow…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
L Crítico vulnerabilidad
17/07/2026
[CVE-2026-8635] IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser…
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve full system compromise with Langflow service permissions.
L Crítico vulnerabilidad
17/07/2026
[CVE-2026-8859] IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to u…
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabled, where filenames extracted from HTTP response Content-Disposition headers are not sanitized before being joined to the temporary director…
L Alto vulnerabilidad
17/07/2026
[CVE-2026-7755] IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete v…
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
L Alto vulnerabilidad
17/07/2026
[CVE-2026-7872] IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files inclu…
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
L Alto vulnerabilidad
17/07/2026
[CVE-2026-8056] IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at…
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function.