Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
03/08/2026
Vulnerabilidad alta de inyección de comandos en Wavlink WL-NU516U1 708c073-mt7628
Se ha identificado una vulnerabilidad de inyección de comandos del sistema operativo en el enrutador Wavlink WL-NU516U1 versión 708c073-mt7628, específicamente en la función de importación de configuración. Un atacante remoto puede manipular el parámetro de contraseña para ejecutar comandos arbitrarios con altos privilegios. La explotación es técnicamente compleja pero el exploit público ya está disponible, aumentando el riesgo para infraestructuras de PYMES y empresas en LATAM que utilizan estos dispositivos.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta de inyección de comandos en GitPython anterior a 3.1.51
GitPython versiones anteriores a 3.1.51 contiene un filtro incompleto contra inyección de comandos que no valida correctamente las abreviaturas de opciones largas de Git. Atacantes pueden ejecutar comandos arbitrarios utilizando nombres de opciones abreviados (ej: upload_p en lugar de upload_pack), afectando sistemas de CI/CD, repositorios corporativos y plataformas DevOps en empresas mexicanas y latinoamericanas que dependen de esta librería para automatización.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-17347] The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an ex…
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the command string and executed the result with subprocess.Popen(..., shell=True). Because the username can …
M Alto vulnerabilidad
31/07/2026
[CVE-2026-16843] Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insuf…
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-14522] IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a …
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-22621] Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PA…
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-22622] Improper input validation in one of the session management interface of Eaton's Tripp Lite series PA…
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44106] A privilege escalation vulnerability in the init-script for user-applications allows a low-privilege…
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44099] A privilege escalation vulnerability in the system configuration allows a low-privileged local user …
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44093] A local privilege escalation vulnerability in the init-script for user-applications allows a low-pri…
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44095] A privilege escalation vulnerability in a script used for network configuration allows a low-privile…
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44096] A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary …
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-44098] This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via …
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-16524] A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the n…
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
M Alto vulnerabilidad
28/07/2026
[CVE-2026-59764] ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability …
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/07/2026
[CVE-2026-61376] ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability …
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-54540] Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is a…
Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then passes the full command string to shell_exec(). Shell command substitution such as $() is not blocked, so an authenticated use…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-55578] Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before versi…
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to shell_exec(). After the fix for GHSA-9643-6xjp-vx57 (which added $ to the blocklist), the characters | (single pipe), ` (backtick), and the newline byte (0x0A) …
M Alto vulnerabilidad
27/07/2026
[CVE-2026-24252] NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A s…
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59687] An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Objec…
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.