Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-78569] IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary cod…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-19136] A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, dist…
A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-73693] FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handle…
FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attackers can upload a file containing command substitution syntax such as backticks, semicolons, or $() sequences in the filename, then trigger the Pho…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-73694] FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinitio…
FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this through an interactive path via image_preview.php with a crafted args parameter requiring superuser authentication, or through…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81467] Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elem…
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81468] Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elem…
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88889] Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that…
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySour…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88885] Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when process…
Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters through malicious dependency names to execute arbitrary commands as the Renovate user during Go module major version updates with postUpdateOptions gomodUpdateImpo…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88886] Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE…
Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module does not escape the distributionUrl value read from a repository's gradle/wrapper/gradle-wrapper.properties file before invoking the Gradle Wrapper CLI. In self-host…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88888] Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processin…
Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names to execute arbitrary commands as the Renovate user in binarySource=docker mode.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64837] ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php,…
ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters in their names and access the Properties function to execute arbitrary commands as the web-server user via popen().
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 permite ejecución de comandos como root
GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad de inyección de comandos que permite a administradores ejecutar código arbitrario con privilegios root mediante caracteres especiales en el nombre de usuario FTP durante actualizaciones de cuenta. Esta vulnerabilidad afecta principalmente a sistemas de vigilancia IP en datacenters y oficinas corporativas en México y Latinoamérica, comprometiendo la integridad y disponibilidad de infraestructura alta de seguridad física.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite ejecución de comandos como root
La cámara GeoVision GV-LPC2211 versión 1.13 permite a administradores inyectar metacaracteres de shell en nombres de usuario que se ejecutan con privilegios root al eliminar la cuenta. Esta vulnerabilidad afecta principalmente sistemas de vigilancia en infraestructuras altas, retail y datos centers en LATAM. El impacto es alta: compromiso total del dispositivo y potencial lateral movement en redes corporativas.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite ejecución de comandos como root
La cámara IP GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad de escape de shell que permite a administradores ejecutar comandos arbitrarios con privilegios root a través del campo de usuario PPPoE. Esta falla afecta principalmente a sistemas de videovigilancia en LATAM, donde estos dispositivos son comúnmente desplegados en infraestructuras altas, puntos de venta y centros de datos.
M Alto vulnerabilidad
10/09/2026
CVE-2026-88274: Ejecución remota de comandos en cámaras GeoVision GV-LPC2211 V1.13
La cámara GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a administradores ejecutar comandos arbitrarios con privilegios de root mediante configuración maliciosa del SSID inalámbrico. Esta falla afecta sistemas de videovigilancia en infraestructuras altas, hospitales y centros financieros en LATAM. Un atacante con acceso administrativo puede comprometer completamente el dispositivo y la red corporativa.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88275] GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to exe…
GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88276] GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to…
GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en cámaras GeoVision GV-LPC2211: inyección de comandos shell
GeoVision GV-LPC2211 versión 1.13 contiene una vulnerabilidad que permite a usuarios ONVIF autenticados inyectar comandos shell a través del parámetro ConsumerReference.Address, resultando en ejecución de código arbitrario con permisos root. Afecta sistemas de vigilancia en infraestructuras altas, acceso remoto corporativo y centros de datos en LATAM.
M Crítico vulnerabilidad
09/09/2026
[CVE-2026-87911] An OS command injection weakness in the read-only enforcement of the SQL validation component in Ama…
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement into content that is processed when an authenticated user interacts with the MCP s…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-23855] Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC…
Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.