<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>El Compilado — Patch Tuesday</title><description>Cada noticia sobre Patch Tuesday del briefing diario de El Compilado.</description><link>https://elcompilado.com</link><language>es</language><item><title>&quot;ShieldBreak&quot;: exploit de 0-day de escalada en Windows liberado justo en el Patch Tuesday</title><link>https://elcompilado.com/blog/briefing-tech-2026-08-14/#shieldbreak-exploit-de-0-day-de-escalada-en-windows</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-08-14/#shieldbreak-exploit-de-0-day-de-escalada-en-windows</guid><description>El grupo Nightmare Eclipse publicó el 13 de agosto un exploit que permite a cualquier usuario abrir una shell con privilegios de System. Puede que ya esté cubierto por los parches del mismo día, pero conviene verificar el estado de aplicación. Va en paralelo con el 0-day de Windows (CVE-2026-68820, AFD.sys) que Lazarus venía explotando contra empresas de defensa y aeroespacial en Francia, Alemania, Brasil e India. SecurityWeek · The Hacker News (Lazarus)

Fuentes: https://www.securityweek.com/nightmare-eclipse-drops-windows-zero-day-exploit-shieldbreak/ · https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>windows</category><category>patch-tuesday</category><category>lazarus</category></item><item><title>Patch Tuesday de agosto: ~400 fallas, 3 zero-days, uno explotado activamente</title><link>https://elcompilado.com/blog/briefing-tech-2026-08-12/#patch-tuesday-de-agosto-400-fallas-3-zero-days</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-08-12/#patch-tuesday-de-agosto-400-fallas-3-zero-days</guid><description>Microsoft parchó cerca de 400 CVEs (SecurityWeek cuenta 421), incluyendo CVE-2026-68820, un use-after-free en el driver afd.sys (WinSock) que permite escalar a SYSTEM. Check Point atribuye la explotación a Lazarus (Corea del Norte), que lo usó para desplegar una nueva versión del rootkit FudModule contra empresas del sector defensa (Operation Dream Job). También se divulgaron públicamente CVE-2026-62832 (User Profile Service) y CVE-2026-72971 (Container Isolation FS Filter). Prioridad: parchear ya. Fuentes: BleepingComputer, SecurityWeek, The Hacker News.

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/ · https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/ · https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html</description><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>patch-tuesday</category><category>lazarus</category></item><item><title>Contexto: Patch Tuesday récord de Microsoft</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-25/#contexto-patch-tuesday-record-de-microsoft</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-25/#contexto-patch-tuesday-record-de-microsoft</guid><description>Como recordatorio de la ventana de parcheo aún vigente, el Patch Tuesday de julio 2026 (14/jul) fue el mayor de la historia de Microsoft, con 570 vulnerabilidades corregidas y tres zero-days, dos de ellos ya explotados activamente (CVE-2026-56155 en AD FS y CVE-2026-56164 en SharePoint Server). Quien no haya parcheado debería priorizarlo. BleepingComputer · ZDI

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-review</description><pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord de Microsoft: ~622 CVEs y 0-days en explotación activa</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-24/#patch-tuesday-record-de-microsoft-622-cves-y-0</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-24/#patch-tuesday-record-de-microsoft-622-cves-y-0</guid><description>El parche de julio fue el mayor de la historia del programa, con cientos de CVEs corregidos e incluyendo dos 0-days ya explotados: CVE-2026-56164 (SharePoint Server on-prem, escalada de privilegios sin autenticación ni interacción del usuario) y CVE-2026-56155 (AD FS, elevación de privilegios). CISA sumó ambos a su catálogo KEV con plazos de remediación inmediatos. Prioridad de parcheo para cualquiera con SharePoint autoalojado. BleepingComputer · The Hacker News · Tenable

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html · https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-cves-cve-2026-56155-cve-2026-56164</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>cisa</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>SharePoint bajo fuego: CVE-2026-58644 explotado como 0-day y sumado al KEV de CISA</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-23/#sharepoint-bajo-fuego-cve-2026-58644-explotado-como-0</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-23/#sharepoint-bajo-fuego-cve-2026-58644-explotado-como-0</guid><description>CISA agregó a su catálogo de vulnerabilidades explotadas un fallo crítico de deserialización en SharePoint (CVSS 9.8) que permite ejecución remota de código y fue armado como zero-day antes del parche. Forma parte de un Patch Tuesday de julio histórico, con Microsoft corrigiendo cientos de CVEs y tres zero-days. The Hacker News · BleepingComputer

Fuentes: https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html · https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>cisa</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord de Microsoft: 622 CVEs y 3 zero-days</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-22/#patch-tuesday-record-de-microsoft-622-cves-y-3</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-22/#patch-tuesday-record-de-microsoft-622-cves-y-3</guid><description>El Patch Tuesday de julio corrigió 622 CVEs —el mayor volumen mensual en la historia de Microsoft, unas tres veces más que el mes previo— incluidos dos 0-days explotados activamente, uno divulgado públicamente y 62 vulnerabilidades críticas. Se recomienda parchear de inmediato. BleepingComputer · Malwarebytes · CrowdStrike

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.malwarebytes.com/blog/bugs/2026/07/july-2026-patch-tuesday-fixes-622-microsoft-cves-including-three-zero-days · https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-july-2026/</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord: 622 CVEs y SharePoint bajo explotación activa</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-21/#patch-tuesday-record-622-cves-y-sharepoint-bajo-explotacion</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-21/#patch-tuesday-record-622-cves-y-sharepoint-bajo-explotacion</guid><description>Microsoft corrigió 622 vulnerabilidades en julio, con 62 críticas y tres zero-days. Dos están bajo explotación activa —CVE-2026-56164 en SharePoint Server y CVE-2026-56155 en ADFS— y CISA las sumó al catálogo KEV con plazos del 17 y 28 de julio para agencias federales. CISA además alertó por explotación activa de varias fallas de SharePoint (CVE-2026-32201, CVE-2026-45659) que permiten RCE y robo de machine keys de IIS para persistencia. También se parchó CVE-2026-55040 (CVSS 9.1), un bypass de autenticación por fallas en la validación de tokens JWT. The Hacker News · BleepingComputer · Zero Day Initiative

Fuentes: https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html · https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>cisa</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>CISA suma un SharePoint CVSS 9.8 al catálogo de explotados activamente</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-20/#cisa-suma-un-sharepoint-cvss-9-8-al-catalogo</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-20/#cisa-suma-un-sharepoint-cvss-9-8-al-catalogo</guid><description>El 17 de julio CISA agregó CVE-2026-58644 (CVSS 9.8) al catálogo KEV: una deserialización de datos no confiables en Microsoft SharePoint Server que permite ejecución remota de código sin autenticación. El plazo para agencias federales venció el 19 de julio. Se suma a los dos zero-days ya explotados del Patch Tuesday de julio: CVE-2026-56164 (SharePoint, EoP) y CVE-2026-56155 (AD FS, EoP, deadline 28 de julio). The Hacker News · BleepingComputer

Fuentes: https://thehackernews.com/search/label/Vulnerability · https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>cisa</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord: 570 fallas y un PoC filtrado horas después</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-20/#patch-tuesday-record-570-fallas-y-un-poc-filtrado</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-20/#patch-tuesday-record-570-fallas-y-un-poc-filtrado</guid><description>Microsoft parcheó un número récord de 570 vulnerabilidades el 14 de julio (59 críticas, 48 de ellas RCE), incluyendo tres zero-days. Horas después del release, un investigador publicó un PoC de un zero-day de Windows adicional, comprimiendo la ventana de exposición para quien no parchee de inmediato. La escala del ciclo reabrió el debate sobre si el tracking de CVEs sigue siendo operativamente viable. BleepingComputer · The Hacker News — PoC · ZDI · Help Net Security

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html · https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-review · https://www.helpnetsecurity.com/2026/07/10/july-2026-patch-tuesday-forecast/</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord de Microsoft: 622 fallos y zero-days en uso</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-19/#patch-tuesday-record-de-microsoft-622-fallos-y-zero</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-19/#patch-tuesday-record-de-microsoft-622-fallos-y-zero</guid><description>Microsoft corrigió 622 vulnerabilidades en julio (casi el triple que junio), incluyendo dos zero-days ya explotados —CVE-2026-56164 (SharePoint) y CVE-2026-56155 (AD FS), ambos de escalada de privilegios sin credenciales ni interacción— y un tercero divulgado públicamente, CVE-2026-50661 (bypass de BitLocker). Además, el 18 de julio CISA agregó al KEV CVE-2026-58644, deserialización crítica en SharePoint Server, con parcheo obligatorio para agencias federales el 19 de julio. BleepingComputer · CISA KEV

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.cisa.gov/known-exploited-vulnerabilities-catalog</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>cisa</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord: ~570 CVEs y dos zero-days explotados</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-18/#patch-tuesday-record-570-cves-y-dos-zero-days</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-18/#patch-tuesday-record-570-cves-y-dos-zero-days</guid><description>Microsoft publicó el mayor Patch Tuesday de su historia (~570 CVEs según su conteo; algunos medios reportan hasta 621), con dos zero-days activamente explotados y uno divulgado públicamente. Los críticos: CVE-2026-56155 (AD FS, escalada de privilegios administrativos) y CVE-2026-56164 (SharePoint Server, elevación remota por falta de autenticación); además CVE-2026-50661 (bypass de BitLocker con acceso físico). Microsoft atribuyó el volumen en parte a un sistema propio de descubrimiento de vulnerabilidades con IA. - -

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-cves-cve-2026-56155-cve-2026-56164</description><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>Patch Tuesday de julio: 570 fallas y 3 zero-days</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-17/#patch-tuesday-de-julio-570-fallas-y-3-zero</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-17/#patch-tuesday-de-julio-570-fallas-y-3-zero</guid><description>Microsoft corrigió 570 vulnerabilidades, con dos zero-days explotados activamente y uno divulgado públicamente. Entre las críticas: CVE-2026-57092 (elevación de privilegios en Windows VMSwitch, CVSS 9.9, cruza el límite de una VM) y CVE-2026-56155 (AD FS, explotada activamente, otorga privilegios administrativos). BleepingComputer · Zero Day Initiative

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-review</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday de Microsoft: récord histórico de 570 fallas y 3 zero-days</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-16/#patch-tuesday-de-microsoft-record-historico-de-570-fallas</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-16/#patch-tuesday-de-microsoft-record-historico-de-570-fallas</guid><description>El paquete de julio corrigió un récord de 570 vulnerabilidades (roughly el triple que junio), con tres zero-days: CVE-2026-56155 (AD FS, escalada a admin), CVE-2026-56164 (SharePoint Server, escalada remota por falta de autenticación) y CVE-2026-50661 (BitLocker, bypass con acceso físico, divulgado públicamente). Dos de ellos ya estaban siendo explotados. Microsoft atribuyó el volumen en parte a un sistema propio de descubrimiento de fallas con IA. BleepingComputer · CrowdStrike

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-july-2026/</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>Patch Tuesday de julio: el mayor de la historia de Microsoft (~570-621 CVEs, 3 zero-days)</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-15/#patch-tuesday-de-julio-el-mayor-de-la-historia</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-15/#patch-tuesday-de-julio-el-mayor-de-la-historia</guid><description>El Patch Tuesday del 14 de julio corrigió un récord de 570 fallos según Microsoft (621 CVEs según el Zero Day Initiative), incluyendo dos zero-days explotados en ataques y uno divulgado públicamente. El más grave es CVE-2026-57092, un use-after-free en Windows VMSwitch (CVSS 9.9) que permite escapar del límite de una VM y comprometer el host. También destacan CVE-2026-56164 (SharePoint, elevación de privilegios sin autenticación) y CVE-2026-56155 (AD FS). Prioridad de parcheo urgente para entornos Windows/virtualización. BleepingComputer · Zero Day Initiative · Security Affairs

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/ · https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-review · https://securityaffairs.com/195347/security/patch-tuesday-security-updates-for-july-2026-the-largest-update-ever-621-cves-in-one-month.html</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>sharepoint</category><category>patch-tuesday</category></item><item><title>Chrome parchea el 0-day CVE-2026-11645 explotado activamente</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-09/#chrome-parchea-el-0-day-cve-2026-11645-explotado</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-09/#chrome-parchea-el-0-day-cve-2026-11645-explotado</guid><description>Google confirmó un acceso a memoria fuera de límites en el motor V8 (JavaScript/WebAssembly) de Chrome, con exploit en circulación. Se recomienda actualizar de inmediato. En paralelo, el Patch Tuesday de junio de Microsoft corrigió un récord de 206 fallos, incluidos tres 0-days y RCE críticos como CVE-2026-45657 (CVSS 9.8, ejecución a nivel SYSTEM). The Hacker News – Chrome · The Hacker News – Microsoft

Fuentes: https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html · https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>google</category><category>microsoft</category><category>chrome</category><category>patch-tuesday</category></item><item><title>Patch Tuesday de julio a la vista tras un junio récord</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-08/#patch-tuesday-de-julio-a-la-vista-tras-un</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-08/#patch-tuesday-de-julio-a-la-vista-tras-un</guid><description>El Patch Tuesday de julio (segundo martes) llega después del mayor lote registrado en junio: 206 vulnerabilidades, 39 críticas y tres 0-days, incluyendo fallos RCE de CVSS 9.8 en Windows HTTP.sys (CVE-2026-47291) y en el cliente DHCP (CVE-2026-44815), más el 0-day &quot;RoguePlanet&quot; (CVE-2026-50656) en el motor de Microsoft Defender. Conviene priorizar el parcheo cuando salgan las actualizaciones de este mes. The Hacker News · Morphisec

Fuentes: https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html · https://www.morphisec.com/blog/microsoft-defender-zero-day-rogueplanet-when-your-detector-becomes-the-attack-surface/</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Microsoft cerró un Patch Tuesday récord de 206 fallos</title><link>https://elcompilado.com/blog/briefing-tech-2026-07-05/#microsoft-cerro-un-patch-tuesday-record-de-206-fallos</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-07-05/#microsoft-cerro-un-patch-tuesday-record-de-206-fallos</guid><description>El último Patch Tuesday incluyó correcciones para 206 vulnerabilidades (39 críticas y tres 0-days públicos), entre ellas CVE-2026-47291 (HTTP.sys, CVSS 9.8) y CVE-2026-44815 (cliente DHCP de Windows, CVSS 9.8), ambas de ejecución remota de código sin autenticación. Prioridad de parcheo alta para administradores de Windows. The Hacker News · Zero Day Initiative

Fuentes: https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html · https://www.thezdi.com/blog/2026/6/9/the-june-2026-security-update-review</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday de junio: récord de 206 CVEs</title><link>https://elcompilado.com/blog/briefing-tech-2026-06-30/#patch-tuesday-de-junio-record-de-206-cves</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-06-30/#patch-tuesday-de-junio-record-de-206-cves</guid><description>Microsoft parcheó 206 vulnerabilidades, incluidas 37 críticas y 3 zero-days públicos. Entre las más graves: CVE-2026-45657 (RCE en el kernel de Windows vía TCP/IP, CVSS 9.8, sin autenticación ni interacción) y CVE-2026-47291 (RCE en HTTP.sys, CVSS 9.8). También se corrigieron tres bypass de BitLocker (CVE-2026-45585 &quot;YellowKey&quot;, CVE-2026-50507 &quot;Bitskrieg&quot;, CVE-2026-45658). Microsoft atribuye el &quot;nuevo normal&quot; de +200 CVEs al hallazgo de bugs asistido por IA. CrowdStrike · ZDI · CSO Online

Fuentes: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2026/ · https://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update-review · https://www.csoonline.com/article/4183632/june-patch-tuesday-marks-a-new-normal-with-over-200-cves-32-rated-critical.html</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord de Microsoft: 206 fallos y zero-days</title><link>https://elcompilado.com/blog/briefing-tech-2026-06-29/#patch-tuesday-record-de-microsoft-206-fallos-y-zero</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-06-29/#patch-tuesday-record-de-microsoft-206-fallos-y-zero</guid><description>La actualización de junio corrigió un récord de 206 vulnerabilidades, incluyendo zero-days divulgados públicamente (uno ligado al exploit &quot;HTTP/2 Bomb&quot;, CVE-2026-49160) y bugs críticos de RCE como CVE-2026-45657 (Windows Kernel, use-after-free, CVSS 9.8) y CVE-2026-44815 (DHCP Client, CVSS 9.8). Importa por el volumen inusual y porque varios fallos son explotables en red sin interacción del usuario. The Hacker News · BleepingComputer

Fuentes: https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html · https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord de Microsoft con RCE críticas</title><link>https://elcompilado.com/blog/briefing-tech-2026-06-28/#patch-tuesday-record-de-microsoft-con-rce-criticas</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-06-28/#patch-tuesday-record-de-microsoft-con-rce-criticas</guid><description>El Patch Tuesday de junio de Microsoft corrigió más de 200 vulnerabilidades, entre ellas CVE-2026-45657 (RCE en el kernel de Windows, CVSS 9.8, ejecución como SYSTEM sin interacción del usuario) y CVE-2026-47291 (RCE en HTTP.sys, CVSS 9.8, remota y no autenticada). Importa por el volumen inédito y por la criticidad de fallos explotables sin interacción. Zero Day Initiative · OpenText

Fuentes: https://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update-review · https://community.opentextcybersecurity.com/vulnerability-vault-228/microsoft-security-update-summary-s-for-june-2026-364467</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord de Microsoft y 0-day de Chrome explotado</title><link>https://elcompilado.com/blog/briefing-tech-2026-06-27/#patch-tuesday-record-de-microsoft-y-0-day-de</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-06-27/#patch-tuesday-record-de-microsoft-y-0-day-de</guid><description>El Patch Tuesday de junio (9/06) batió récord con ~206 CVEs y seis 0-days, incluidos RCE críticos sin interacción del usuario (CVE-2026-45657, CVE-2026-47291, ambos CVSS 9.8). En paralelo, Google parcheó de emergencia un 0-day en el motor V8 de Chrome (CVE-2026-11645, CVSS 8.8) que ya se explotaba en la práctica. BleepingComputer · The Hacker News

Fuentes: https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/ · https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html</description><pubDate>Sat, 27 Jun 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>google</category><category>microsoft</category><category>chrome</category><category>patch-tuesday</category></item><item><title>Patch Tuesday récord de Microsoft: 206 vulnerabilidades y varios 0-days</title><link>https://elcompilado.com/blog/briefing-tech-2026-06-26/#patch-tuesday-record-de-microsoft-206-vulnerabilidades-y-varios</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-06-26/#patch-tuesday-record-de-microsoft-206-vulnerabilidades-y-varios</guid><description>La actualización de junio corrigió 206 fallos (39 críticos) e incluyó zero-days divulgados públicamente. El más comentado es CVE-2026-49160 (&quot;HTTP/2 Bomb&quot;), un DoS en el listener kernel HTTP.sys de Windows; también se parchearon CVE-2026-45586 (&quot;GreenPlasma&quot;), una elevación de privilegios a SYSTEM, y CVE-2026-50507 (&quot;YellowKey&quot;), un bypass de BitLocker. (The Hacker News, BleepingComputer, SOCRadar)

Fuentes: https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html · https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/ · https://socradar.io/blog/june-2026-patch-tuesday-zero-day/</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday de junio: Microsoft corrige 206 vulnerabilidades, 3 zero-days</title><link>https://elcompilado.com/blog/briefing-tech-2026-06-23/#patch-tuesday-de-junio-microsoft-corrige-206-vulnerabilidades-3</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-06-23/#patch-tuesday-de-junio-microsoft-corrige-206-vulnerabilidades-3</guid><description>El parche de junio incluye 37 fallos críticos y tres zero-days divulgados públicamente. Entre los más graves, CVE-2026-47291 (RCE en HTTP.sys, CVSS 9.8) y CVE-2026-45657 (RCE en el kernel de Windows, CVSS 9.8), ambos explotables de forma remota sin autenticación. Parcheo prioritario para entornos Windows expuestos. CrowdStrike · Zero Day Initiative

Fuentes: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2026/ · https://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update-review</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item><item><title>Patch Tuesday gigante de Microsoft</title><link>https://elcompilado.com/blog/briefing-tech-2026-06-22/#patch-tuesday-gigante-de-microsoft</link><guid isPermaLink="true">https://elcompilado.com/blog/briefing-tech-2026-06-22/#patch-tuesday-gigante-de-microsoft</guid><description>Junio trajo ~206 vulnerabilidades parcheadas, 37 críticas y 3 zero-days públicos. Las dos más serias son RCE con CVSS 9.8: CVE-2026-45657 (use-after-free / heap overflow en el kernel de Windows, ejecución remota sin interacción del usuario a nivel SYSTEM) y CVE-2026-47291 (integer/heap overflow en HTTP.sys, también RCE sin autenticar). Priorizar el parcheo. CrowdStrike · Zero Day Initiative

Fuentes: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2026/ · https://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update-review</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>ciberseguridad</category><category>microsoft</category><category>windows</category><category>patch-tuesday</category></item></channel></rss>