Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Google" — 1248 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95282] Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to exec…
Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-95283] Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attac…
Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95274] Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attack…
Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
29/09/2026
[CVE-2026-95276] Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacke…
Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100705] Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (16…
Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only into the new CEL http.Get/Post library and were never applied to the legacy apiCall service executor (pkg/engine/apicall/executor.go) or to the GlobalContextEntry external-API…
M Alto vulnerabilidad
26/09/2026
Vulnerabilidad alta en OpenClaw 2026.5.1-2026.7.0 omite validación de comandos Google Meet
OpenClaw versiones 2026.5.1 a 2026.7.0 no aplican la ruta de aprobación configurada para comandos del nodo Google Meet, permitiendo que arrays de audio suministrados por atacantes se ejecuten sin validación en nodos Chrome emparejados. En despliegues con el plugin de Google Meet activo, esto expone las videollamadas empresariales y sistemas de comunicación a ejecución de código no autorizado. El impacto es alta (CVSS 8.8) en organizaciones LATAM que dependen de infraestructura de comunicaciones unificadas.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad de Inclusión de Archivos Locales en Plugin WP Maps para WordPress
El plugin WP Maps (versiones hasta 4.9.8) presenta una vulnerabilidad de Local File Inclusion (LFI) que permite a atacantes autenticados con acceso de suscriptor ejecutar archivos PHP arbitrarios en el servidor mediante el parámetro 'page'. Esta falla afecta directamente a sitios WordPress que utilizan este plugin en México y LATAM para gestionar ubicaciones de tiendas y directorios, comprometiendo la integridad del servidor y acceso a datos sensibles.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-86708] ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of …
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
G Crítico vulnerabilidad
17/09/2026
[CVE-2026-93372] Vulnerabilidad Android en Android OS - CVSS 9.6
Vulnerabilidad de seguridad en Android (Android OS): Desbordamiento de Buffer. CVSS: 9.6. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
G Crítico vulnerabilidad
17/09/2026
[CVE-2026-93374] Vulnerabilidad Android en Android OS - CVSS 9.6
Vulnerabilidad de seguridad en Android (Android OS): Use-After-Free (UAF). CVSS: 9.6. Afecta dispositivos Android, 80%+ del mercado movil en Mexico y LATAM. Actualiza tu dispositivo en Ajustes - Actualizacion del sistema.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-90046] In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylo…
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP". Pre-existing bugs found by Sashiko during review of this other series: https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/ I have not reproduced these bugs, and I suspect there is …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91743] Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had com…
Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91748] Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote atta…
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91749] Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to poten…
Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91735] Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker w…
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91736] Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute a…
Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91741] Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to …
Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-91728] Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute …
Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91731] Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to e…
Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91733] Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker …
Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)