Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 31 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94084] Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by r…
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88097] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privile…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-19666] On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is …
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-85893] Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privile…
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91749] Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to poten…
Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91736] Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute a…
Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91721] Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to pot…
Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91724] Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had co…
Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-58724] In multiple locations, there is a possible use-after-free due to a race condition. This could lead t…
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55318] In multiple locations, there is a possible use-after-free due to a race condition. This could lead t…
In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91087] A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_i…
A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version abi-16.24 is able to resolve this issue. This patch is called e34f4b…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90852] A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the func…
A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after free. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.7-14 is able to resolve this issu…
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta de Use After Free en Open5GS 2.7.x y anteriores
Se descubrió un fallo de seguridad (CVE-2026-90707, CVSS 8.3) en Open5GS que afecta la función amf_nnrf_try_old_amf_discovery_fallback, permitiendo ataques remotos de Use After Free mediante manipulación del parámetro discovery_option. Este componente es alta en infraestructuras 5G, poniendo en riesgo operadores de telecomunicaciones y proveedores de servicios móviles en LATAM que dependan de esta solución open source.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-57842] NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPA…
NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD system can trigger a kernel panic or memory corruption by calling recvmsg() with msg_iovlen between 9 and IOV_MAX, causing …
M Alto vulnerabilidad
11/09/2026
[CVE-2026-78133] libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handlin…
libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-87933] A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJS…
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87877] zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and…
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87825] zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a d…
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corrupti…
G Crítico vulnerabilidad
09/09/2026
[CVE-2026-87646] Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attack…
Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
09/09/2026
[CVE-2026-87648] Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attac…
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)