Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85656] An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.…
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85696] SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded …
SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85672] zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the…
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occu…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85660] cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with…
cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation check.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-62928] XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injec…
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85439] MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::…
MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the --dir parameter to execute arbitrary commands with the privileges of the operator running alogsplit.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85425] MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable…
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85426] MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names w…
MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets in system calls.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85223] A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functio…
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85224] A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part o…
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85222] A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unkn…
A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85012] Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthe…
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-71963] Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulner…
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh wh…
M Alto vulnerabilidad
03/09/2026
[CVE-2025-12737] The administrative operations within the Carbon Console do not adequately validate specific user-sup…
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta de inyección de comandos en Nuclio anterior a v1.17.4
Nuclio, framework serverless para procesamiento de eventos en tiempo real, contiene una vulnerabilidad de inyección de comandos del shell en versiones anteriores a 1.17.4. Un atacante remoto puede ejecutar comandos arbitrarios en el host Docker explotando la interpolación no validada del namespace en comandos docker ps. El riesgo es alta en entornos con autenticación deshabilitada (configuración por defecto).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52831] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, ). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This iss…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84837] A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing th…
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with t…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84838] A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to e…
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84675] OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able…
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-53611] Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary…
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in the input…