Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79641] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87088] Tanium addressed an unauthorized code execution vulnerability in Enforce.
Tanium addressed an unauthorized code execution vulnerability in Enforce.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-82004] Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in a…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81349] Improper neutralization of special elements used in an os command ('os command injection') in Azure …
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86733] Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/…
Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST …
M Alto vulnerabilidad
08/09/2026
[CVE-2026-61517] Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the…
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell commands as root by injecting into the IpAddr parameter. The parameter is interpolated directly into a shell command executed through system() with an incomplete denylist that only blocks spaces, pipes, semi…
M Crítico vulnerabilidad
08/09/2026
Inyección de comandos OS crítica en Cosminexus Component Container (CVE-2026-71376)
Una vulnerabilidad de inyección de comandos del sistema operativo (CVSS 9.8) afecta múltiples versiones de Cosminexus Component Container, permitiendo a atacantes ejecutar comandos arbitrarios con privilegios de la aplicación. La falla impacta versiones desde 11-70-01 hasta 09-80 y anteriores. Empresas en LATAM que usan este middleware de aplicaciones para sistemas críticos deben aplicar parches inmediatamente.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-76561] A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificat…
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achievi…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86540] knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project co…
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80127] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-19843] A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch comm…
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the e…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-61409] Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Imprope…
Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
M Crítico vulnerabilidad
07/09/2026
Inyección de comandos OS crítica en Linksys RE7000 2.0.15 permite ejecución remota
Se ha identificado una vulnerabilidad crítica (CVSS 9.9) en el repetidor inalámbrico Linksys RE7000 versión 2.0.15. Un atacante remoto puede inyectar comandos del sistema operativo manipulando parámetros de prueba ping (pingTestIp, pingTestPktSize, pingTestTimes) en el componente /cgi-bin/json.cgi?PingTest. El exploit es público y activamente explotado, afectando infraestructuras de redes corporativas y MiPyMEs en México y Latinoamérica que dependan de este dispositivo.
M Crítico vulnerabilidad
06/09/2026
Inyección de comandos OS crítica en Tenda HG10 (CVE-2026-86167)
Se identificó una vulnerabilidad crítica (CVSS 9.9) en el router Tenda HG10 modelo 300001138 que permite inyección de comandos del sistema operativo a través del parámetro fmgpon_loid en la función formgponConf. La vulnerabilidad es explotable remotamente y cuenta con exploits públicos disponibles. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan estos equipos en infraestructuras de acceso a internet.
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-86152] A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::T…
A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-86151] A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77…
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-86148] A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the functio…
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.
M Crítico vulnerabilidad
05/09/2026
[CVE-2026-86149] A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing …
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-53932] laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1…
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-78327] An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution.