Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
14/08/2026
[CVE-2026-73680] Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration th…
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sani…
M Alto vulnerabilidad
14/08/2026
[CVE-2026-17179] IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial…
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19679] An input validation vulnerability exists in Security Center's file upload handling, where insufficie…
An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19635] A local privilege escalation vulnerability exists in Security Center. An attacker with write access …
A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19628] A command injection vulnerability exists in Tenable Security Center. An authenticated administrator …
A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19771] A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown fun…
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure bu…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73667] OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and …
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parameters into shell program text executed through sh -c instead of passing the values through container.env, allowing arbitrary commands to run in workflow p…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73570] A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the o…
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands a…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-53790] rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attac…
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell command newline injection. Attackers can inject shell metacharacters or newline characters into uns…
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad alta en GitPython permite ejecución de comandos arbitrarios en operaciones de clonación
GitPython versiones anteriores a 3.1.54 contiene una denylist incompleta que omite la opción --template, permitiendo a atacantes ejecutar comandos arbitrarios mediante hooks maliciosos durante operaciones de clonación. Esta vulnerabilidad afecta directamente a sistemas CI/CD, pipelines de desarrollo y servidores que utilizan GitPython para automatizar gestión de repositorios, siendo alta en entornos DevOps de empresas en LATAM que dependen de flujos de integración continua.
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad alta de ejecución remota de código en GitPython anteriores a 3.1.54
GitPython versiones anteriores a 3.1.54 contiene una vulnerabilidad de ejecución remota de código (RCE) que permite a atacantes eludir validaciones de seguridad mediante opciones git manipuladas. Los métodos clone_from, fetch, pull, push, ls_remote, iter_commits, blame y archive pueden ser explotados para ejecutar comandos arbitrarios del sistema operativo. Empresas en LATAM que usen GitPython en pipelines CI/CD, sistemas de gestión de repositorios o herramientas de DevOps están en riesgo alta de comprometer servidores y datos sensibles.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16695] IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbit…
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13476] IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute ar…
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17417] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary comman…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17642] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary comman…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-12005] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a malicious HTTP request.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18235] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Contro…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-17248] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of servic…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16856] IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutrali…
IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16906] IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with el…
IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.