Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 24 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
D Alto vulnerabilidad
23/06/2026
[CVE-2026-49402] Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_proces…
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn / spawnSync / exec and friends. On Windows, the helper failed to quote arguments that contained cmd.exe metacharacters and did not neutralize % (which cmd.exe expands even inside double-quoted strings)…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-35018] NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code ex…
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands as root by injecting shell metacharacters into the username JSON parameter processed by the dalStorage_addUserAccount function. Attackers can exploit the unsafe concatenation of user-supplied input into a shell c…
I Alto vulnerabilidad
23/06/2026
[CVE-2026-56379] ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG deco…
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
F Crítico vulnerabilidad
23/06/2026
[CVE-2026-56274] Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server…
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for ex…
M Alto vulnerabilidad
19/06/2026
[CVE-2026-49260] PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version …
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX `escapeshellarg('/usr/local/bin/weasyprint')` returns `'/usr/local/bin/weasyprint'` with the …
M Alto vulnerabilidad
17/06/2026
[CVE-2026-48997] e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection v…
e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destination path. In resize_image(), the source path is escaped with escapeshellarg(), but the destination path is inserted inside raw double quotes in the convert command; in the submit-news upload flow, that destination filename includes the first six charact…
S Crítico vulnerabilidad
17/06/2026
[CVE-2026-20266] In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute ar…
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-55743] The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (de…
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe() blocks the find flags -exec and -ok but not the functionally identical -execdir and -okdir, which also…
M Alto vulnerabilidad
17/06/2026
[CVE-2026-53876] RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may…
RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.
T Alto vulnerabilidad
17/06/2026
[CVE-2026-11409] An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler i…
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
T Alto vulnerabilidad
17/06/2026
[CVE-2026-11410] An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configurat…
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-22313] The device has a webserver that exposes a REST API authenticated with a token on the management netw…
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
M Alto vulnerabilidad
16/06/2026
[CVE-2026-44932] Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 co…
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
M Alto vulnerabilidad
16/06/2026
[CVE-2026-12398] A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the lega…
A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution o…
M Alto vulnerabilidad
16/06/2026
[CVE-2026-5416] Due to the improper neutralization of special elements used in a name parameter a low privileged rem…
Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
D Alto vulnerabilidad
16/06/2026
[CVE-2026-12161] Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permis…
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This affects  :  - Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0 - Remote…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-48723] The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on Browse…
The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a shell command by interpolating the user-controlled cypress_config_filepath value into a template literal, t…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50874] An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Remi…
An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38060] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlo…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38061] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.