Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76219] GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from…
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to overwrite arbitrary files with a valid git-index blob, destroying existing file …
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76220] GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard…
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_from to emit a joined token parsed as --upload-pack, enabling arbitrary OS command execution at default allow_unsafe_option…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75912] CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool t…
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values like --contents=/path/to/file to exfiltrate sensitive files such as SSH keys and credentials through the tool output returned to the model.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-73682] Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerabili…
Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git's --upload-pack= option to inject and execute arbitrary shell …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-53790] rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attac…
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into uns…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-53783] rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in …
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink for a path component after validation but before transfer processing. Attackers can additionally leverage unrestricted flags such as --copy-unsafe-links, -D, and …
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad alta en GitPython: sobrescritura arbitraria de archivos en versiones anteriores a 3.1.54
GitPython anterior a la versión 3.1.54 contiene una vulnerabilidad que permite a atacantes sobrescribir archivos arbitrarios mediante el método Diffable.diff, explotando la falta de validación de opciones git. Un atacante puede ejecutar esta acción con los permisos del proceso, afectando sistemas de control de versiones en empresas que usen esta librería en pipelines de CI/CD, especialmente en entornos cloud y DevOps de México y Latinoamérica.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-16770] PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in…
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through _pdf_webkit_meta_tags and turns each one into a wkhtmltopdf command line option. KEY is normalized to an option name matching --[…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73294] Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, reposi…
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/repositories and scheduled commit-hash polling, allowing a project Manager or Owner to execute arbitrary OS commands in the Semaphore server process. This i…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72538] An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to…
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The branch parameter is passed directly to git pull without sanitization, enabling injection of arbitrary git arguments. This represents a distinct code path from the incomplete fix applied for CVE-2026-5366 and allows command …
M Alto vulnerabilidad
31/07/2026
[CVE-2026-17347] The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an ex…
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can …
M Alto vulnerabilidad
31/07/2026
[CVE-2026-18157] A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the s…
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the…
A Alto vulnerabilidad
27/07/2026
[CVE-2026-43698] An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7…
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to gain root privileges.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16796] Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock Agent…
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to the patched version 1.18.1.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-44189] A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider…
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. Th…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-16493] A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's conc…
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An attacker who provides a crafted collection source URI containing git argument injection payloads can achieve arbitrary command e…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-15793] BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true whe…
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.
F Alto vulnerabilidad
20/07/2026
[CVE-2026-64624] FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line opt…
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
M Crítico vulnerabilidad
15/07/2026
[CVE-2026-52891] Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embe…
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/fileValidation.js used a shell command with the avatar filename, shell metacharacters such as backticks and $() in the filename could execute commands on the serve…
M Alto vulnerabilidad
15/07/2026
[CVE-2026-50147] Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57…
Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe JDBC parameters to a MySQL or MariaDB connection, causing the driver to read files from the Metabase host and expose the…