Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90618] A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This…
A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issu…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90619] A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.…
A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product i…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83948] Improper neutralization of special elements used in a command ('command injection') in Microsoft Azu…
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69534] Improper neutralization of special elements used in a command ('command injection') in Windows Progr…
Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-84387] A improper neutralization of special elements used in a command ('command injection') vulnerability …
A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to execute unauthorized code or commands via
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86427] LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter tha…
LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF and LINE arguments to read RRD files from unauthorized devices, or use newline injection to execute arbitrary rrdtool commands, bypassing per-device authorization…
M Alto vulnerabilidad
07/09/2026
Vulnerabilidad alta de inyección de comandos en router D-Link DIR-895L A1_102b07
Se identificó una vulnerabilidad de inyección de comandos (CVSS 8.3) en el componente udhcpcd del router D-Link DIR-895L modelo A1_102b07, explotable remotamente a través de la manipulación del parámetro Hostname. El exploit público ya está disponible, aumentando el riesgo de compromiso de equipos de red corporativos y PYMES en LATAM que utilizan este modelo para conectividad alta.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-53932] laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1…
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-79682] Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privi…
Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-10195] The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and incl…
The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpeg path parameter before passing it to the exec() function, combined with missing authorization checks on the REST API endpoints. This makes it possible for authenticated attackers, with subscriber-level access and above, to exec…
M Alto vulnerabilidad
01/09/2026
Ejecución remota de código en LibreNMS antes de v26.5.0 por validación insuficiente
LibreNMS en versiones anteriores a 26.5.0 contiene una vulnerabilidad de ejecución remota de código (RCE) en el controlador AboutController. El parámetro de configuración snmpget se pasa directamente a shell_exec() sin validación, permitiendo que un administrador autenticado ejecute comandos arbitrarios a través del endpoint /about apuntando a ejecutables maliciosos. Afecta principalmente a proveedores de servicios de monitoreo y operadores de infraestructura en LATAM que ejecutan LibreNMS en entornos de producción.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad alta de inyección de comandos en ICP DAS UA-2200 y UA-5200
Se ha identificado una vulnerabilidad de inyección de comandos remota en los controladores ICP DAS UA-2200 y UA-5200 hasta la versión 20260704. El fallo reside en la función ArmAngstromInstructionSet del endpoint /CGI?RestApi=SetHostname, permitiendo manipulación del parámetro ParameterArray para ejecutar comandos con privilegios del servicio. La vulnerabilidad tiene exploits públicamente disponibles y afecta principalmente a sistemas de automatización industrial y control remoto en plantas, infraestructura alta y manufactura en LATAM.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82668] A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerab…
A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is the function getDefaultBranch of the file src/SCM/System/Git/CommandLine.php of the component Git Command Line. Such manipulation leads to os command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.0.0-beta addr…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82597] A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function …
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82595] A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function s…
A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-50979] A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.…
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
M Alto vulnerabilidad
25/08/2026
Inyección de comandos alta en TOTOLIK N600R 4.3.0cu.7647_B20210106
Se detectó una vulnerabilidad de inyección de comandos en routers TOTOLINK N600R versión 4.3.0cu.7647_B20210106 a través del parámetro ntp_server en /cgi-bin/cstecgi.cgi. Un atacante remoto puede ejecutar comandos arbitrarios sin autenticación, comprometiendo completamente el dispositivo. Esta vulnerabilidad afecta especialmente a PyMEs y centros de datos en LATAM que usan estos equipos como punto de acceso o pasarela de red.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-24169] NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated …
NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject code by sending a specially crafted API request. A successful exploit of this vulnerability might lead to code execution, escalation of privileges and information disclosure.
M Alto vulnerabilidad
23/08/2026
[CVE-2026-78141] A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of th…
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
23/08/2026
Inyección de comandos alta en Tenda CH22 1.0.0.1 permite acceso remoto no autorizado
Se ha identificado una vulnerabilidad de inyección de comandos en el router Tenda CH22 versión 1.0.0.1 a través de la función formeditFileName del archivo /goform/editFileName. Un atacante remoto puede ejecutar comandos arbitrarios manipulando el parámetro editNameMit sin autenticación previa. El exploit ha sido publicado públicamente, incrementando el riesgo de explotación masiva en infraestructuras de LATAM que utilizan este modelo de router.