Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-81537] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-80412] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-80425] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-80379] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-77601] OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or mor…
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in openc3/lib/openc3/models/plugin_model.rb to interpolate the value into a shell command while installing a p…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93349] Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console…
Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the user who explores it. Attackers can place shell metacharacters in resource path values within a datapackage.json descriptor, which are passed unsanitized to os.system…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-76978] ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to…
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/09/2026
Vulnerabilidad alta de inyección de comandos OS en CGServiSign de Changing (CVE-2026-15027)
CGServiSign, desarrollado por Changing, contiene una vulnerabilidad de inyección de comandos OS (CVSS 8.8) que permite a atacantes no autenticados ejecutar comandos arbitrarios en computadoras locales mediante ingeniería social. La explotación requiere que la víctima visite una página web maliciosa que interactúe con la interfaz del servicio local, representando riesgo alta para empresas en LATAM que utilizan esta herramienta en estaciones de trabajo y servidores.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94367] OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulner…
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-16468] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to OS command injection.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-16469] IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker t…
IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17102] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-76714] Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users…
Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-65130] NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS…
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
M Alto vulnerabilidad
21/09/2026
[CVE-2026-55897] luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to r…
luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in applications/luci-app-advanced-reboot/root/usr/share/rpcd/acl.d/luci-app-advanced-reboot.json grants rpcd file.exec permission f…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/09/2026
[CVE-2026-62182] KubeEdge is an open source system for extending native containerized application orchestration capab…
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into the keadm config-update command and executes it through a system shell. A user wit…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-62371] KubeEdge is an open source system for extending native containerized application orchestration capab…
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and spec.image values into the keadm upgrade edge shell command. A user with permissio…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-82412] ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability…
ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate and pass it through validateSingleWord, which permits shell metacharacters. scripts/lua/modules/vulnerability_scan/…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-84285] An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 cou…
An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta de inyección de comandos OS en getID3 anterior a 1.9.26
getID3 versiones anteriores a 1.9.26 contiene una vulnerabilidad de inyección de comandos del sistema operativo en manejadores shell que no escapan correctamente nombres de archivo en cadenas de comando. Atacantes pueden crear nombres de archivo maliciosos con metacaracteres de shell para inyectar comandos arbitrarios ejecutados con los privilegios del proceso que integra getID3. Esta vulnerabilidad afecta principalmente a servidores web y aplicaciones de procesamiento de multimedia en empresas de LATAM que utilizan librerías PHP desactualizadas.