Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2026-85013] A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing …
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57586] CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior t…
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and p…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-55158] Conflibot warns in advance when merging a pull request will cause conflicts in other open pull reque…
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a…
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad alta de inyección de comandos en PraisonAI (CVE-2026-57133)
PraisonAI versiones 1.5.1 a 1.7.2 contienen una vulnerabilidad de inyección de comandos en la función shell() que permite eludir validaciones de lista blanca. Un atacante puede ejecutar comandos arbitrarios prefijando su payload con un comando permitido. Afecta especialmente a equipos que utilizan PraisonAI en pipelines de automatización altas en empresas de tecnología, fintech y servicios en LATAM.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57136] PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-t…
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an allowed executable can append a non-allowlisted command through shell metacharacters,…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-19515] The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input …
The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit test execution flow. Successful exploitation of this vulnerability could lead to the execution of arbitrary OS commands o…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-77853] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-90847] A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown functio…
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90843] A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b89…
A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Th…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-17133] IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a …
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-16466] IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacke…
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to os command injection.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54182] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which i…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-59960] Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.…
Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseCommitSha() when hasRemoteContentAccess is false. The gitFetch() and gitMergeBase() functions in packages/core/src/ci-environment/git.ts interpolate these values into …
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57124] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose PO…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. Because the UI commands bind to 0.0.0.0 by default, a reachable unauthenticated client can execute commands as the UI service …
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta en Parallels Desktop: escalada de privilegios local vía socket mundial
Parallels Desktop ejecuta el servicio prl_disp_service con permisos root a través de un socket accesible mundialmente (/var/run/prl_disp_service.socket), permitiendo a usuarios locales ejecutar comandos arbitrarios sin validación de firma ni pertenencia a grupos administrativos. La vulnerabilidad afecta principalmente a empresas en México y LATAM que usan Parallels Desktop en infraestructuras de desarrollo, testing y virtualización en macOS, exponiendo sistemas con múltiples usuarios o acceso compartido.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 1.1.52 permite ejecución remota
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 versión 1.1.52 que permite inyección de comandos del sistema operativo a través de la función /boafrm/formDiskFormat. Un atacante remoto puede manipular el parámetro 'partition' para ejecutar comandos arbitrarios sin autenticación. El exploit está publicado y activamente en uso.
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 versión 1.1.52 (CVE-2026-90703)
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 1.1.52 que permite inyección de comandos del sistema operativo a través del parámetro folderpath en la función de creación de comparticiones de disco. El ataque es remotamente exploitable y el exploit público ya circula en la comunidad de seguridad. Esta vulnerabilidad afecta principalmente a PyMES y empresas en LATAM que utilizan estos equipos como gateways de red.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en D-Link DWR-M920 1.1.7 permite inyección de comandos OS
Se identificó una debilidad en el enrutador D-Link DWR-M920 versión 1.1.7 que permite inyección de comandos del sistema operativo a través del parámetro newPin en la función /boafrm/formPinManageSetup. El ataque puede ejecutarse remotamente sin autenticación y el exploit ya está disponible públicamente. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan este modelo para conectividad de sucursales.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90690] A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.…
A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument additional_args/target/username/password/scan_type/payload can lead to os command injection. The attack can be launched remotely. The e…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82791] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.