Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102096] Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticat…
Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103473] Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child…
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100254] In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute command…
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102874] A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of th…
A vulnerability was identified in HKUDS AnyTool 0.1.0. Affected is the function subprocess.run of the file anytool/local_server/main.py of the component Execute Endpoint. The manipulation of the argument command/shell leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early thro…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102925] virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the genera…
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path reaches __VIRTUAL_ENV__ when a relocated environment's recorded directory is absent; in the fish scrip…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100292] In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through …
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102826] simple-git, an interface for running git commands in any node.js application, enables applications t…
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and t…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84422] IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME re…
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84440] IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification …
IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges.
M Alto vulnerabilidad
29/09/2026
[CVE-2022-51019] Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation an…
Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell command execution. Authenticated users with admin panel access can inject shell metacharacters into the alias parameter to execute arbitrary commands on the server.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-86035] Weblate is a web-based continuous localization platform used to manage software translations. Weblat…
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-82804] The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization…
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102437] OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSe…
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en shell-quote permite inyección de comandos via función quote()
La función quote() de la librería shell-quote procesa incorrectamente tokens de comentario, permitiendo que un atacante inyecte comandos shell arbitrarios mediante saltos de línea en cadenas de texto. Esta vulnerabilidad afecta aplicaciones Node.js en servidores de LATAM que utilizan shell-quote para sanitización de argumentos, pudiendo comprometer sistemas de CI/CD, contenedores Docker y plataformas de automatización.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-87741] The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versi…
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-55157] Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live…
Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute arbitrary shell commands through the username argument of the get-user-info operation. …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-4556] Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privile…
Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which communicates with the application via XPC. The [ConsoleLogHelper copyConsoleIntoFileFromStartDate:] method executes a syslog command using attacker-controlled parameters without proper sanitization, enabling command injection. Successful exploitation allows a local attacker to exec…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-86330] An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_int…
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can p…
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en NeuVector permite inyección de comandos OS en contenedores privilegiados
NeuVector versiones 5.4 (anteriores a 5.4.11) y 5.5 presenta manejo inadecuado de parámetros que permite a usuarios autenticados con permisos de escritura en Políticas Runtime o acceso a claves gRPC internas inyectar comandos del sistema operativo en contenedores enforcer privilegiados. Esto resulta en compromiso total del nodo worker. Afecta principalmente a infraestructuras containerizadas en Azure, AWS y datacenters locales de la región.
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad alta en productos Wi-Fi BUFFALO permite ejecución remota de comandos
BUFFALO Wi-Fi products procesa incorrectamente entradas en formularios web para construir cadenas de comandos del sistema operativo, permitiendo a usuarios administrativos ejecutar comandos OS arbitrarios mediante solicitudes HTTP maliciosamente elaboradas. Afecta principalmente a infraestructuras de conectividad en pequeñas y medianas empresas (PYMES) de México y Latinoamérica que utilizan equipos BUFFALO para redes corporativas.