Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84675] OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able…
OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.
M Alto vulnerabilidad
02/09/2026
[CVE-2025-46418] Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84694] Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands exec…
Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside containers.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-83549] Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command I…
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-58567] Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited p…
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84233] A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containin…
A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integ…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-58571] Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited p…
Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/09/2026
Inyección de comandos OS alta en yast2-users (CVE-2026-59680)
Se identificó una vulnerabilidad de inyección de comandos en yast2-users que afecta la gestión de usuarios en sistemas Linux basados en SUSE. La función get_password_term() no valida campos numéricos (shadowLastChange, shadowExpire), permitiendo ejecución arbitraria de comandos del sistema operativo con privilegios elevados. Afecta directamente servidores administrados en México y LATAM que utilicen esta herramienta.
M Alto vulnerabilidad
01/09/2026
Inyección de comandos OS alta en yast2-auth-client comprometería servidores con Active Directory
Una vulnerabilidad de inyección de comandos del sistema operativo en yast2-auth-client (CVSS 8.8) permite a atacantes que controlen valores de configuración de Active Directory ejecutar comandos arbitrarios como root en hosts configurados. El componente Auth::AuthConf interpola directamente valores de configuración en invocaciones de comandos Samba sin sanitización, afectando principalmente servidores Linux/Unix en entornos corporativos que integran autenticación con infraestructuras AD en LATAM.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad alta en yast2-samba-client permite ejecución de comandos como root
Una falla de neutralización de caracteres especiales en yast2-samba-client (versiones hasta 5.0.4) permite a un atacante con control sobre un controlador de dominio Active Directory malicioso ejecutar comandos arbitrarios con privilegios root en máquinas siendo unidas al dominio. Afecta directamente servidores Linux en entornos corporativos que integran Active Directory, común en infraestructuras híbridas de LATAM con dominios Windows centralizados.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-19702] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerabi…
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82668] A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerab…
A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is the function getDefaultBranch of the file src/SCM/System/Git/CommandLine.php of the component Git Command Line. Such manipulation leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.0.0-beta addr…
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82636] Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm cal…
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-linux/file-copy-vm/qfile-dom0-agent.c.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75486] Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker wh…
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters..optic-ci.original branch name field. The expectGitBranch() function in src/lint.ts passes the unsanitized branch name directly into child_process.exec() via an unescape…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75121] PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vul…
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a crafted memberTags value to execute arbitrary operating-system commands on the devi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75122] PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vul…
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with administrator web credentials can submit a crafted certificate upload request to execute…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75123] PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vul…
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A remote attacker with administrator web credentials can send a crafted SMTP server value to execute arbitrary operating-system c…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-38820] openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injec…
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-38822] In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the au…
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-78037] Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. A…
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.