Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta en dracut permite ejecución de comandos con privilegios root
Se descubrió una falla en dracut donde la función de manejo de errores die() no realiza escape adecuado de caracteres especiales en mensajes, permitiendo inyección de comandos a través de la opción DHCP ROOT_PATH. Un atacante en la red local controlando un servidor DHCP rogue puede ejecutar comandos arbitrarios con privilegios root durante el siguiente arranque del sistema, afectando servidores de infraestructura alta en data centers de LATAM.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-63725] sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around …
sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-concatenating the backup directory path $this->path directly into the command line ('tar czf ' . $backupFileApp . ' ' . BASE_PATH . ' --exclude \"' . $this->path . '\" 2>&1') and passes the result to PHP's exec() with no application of escapeshellarg() a…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19036] A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C…
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de inyección de comandos en Shibby Tomato 1.28.0000
Se identificó una vulnerabilidad de inyección de comandos del sistema operativo en Shibby Tomato 1.28.0000 a través del parámetro new_qoslimit_enable en la función new_qoslimit_start del archivo /etc/qoslimit. Esta falla permite a atacantes remotos ejecutar comandos arbitrarios con privilegios del router, afectando principalmente a empresas y proveedores de servicios en LATAM que utilizan este firmware en equipos de red altas. El exploit está disponible públicamente.
M Alto vulnerabilidad
06/08/2026
Inyección de comandos OS en Shibby Tomato 1.28.0000 permite ejecución remota
Se identificó una vulnerabilidad de inyección de comandos en Shibby Tomato 1.28.0000 que afecta la función new_qoslimit_stop en /tmp/qoslimittc_stop.sh. Un atacante remoto puede manipular el parámetro wan_iface para ejecutar comandos del sistema operativo con privilegios del dispositivo. El exploit es público y activamente utilizado. Nota: Este proyecto ha sido descontinuado en favor de FreshTomato.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71312] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths into PowerShell hash commands in backend/sftp/sftp.go, and quoteOrEscapeShellPath escapes only ASCII apostrophe even though PowerShell treats U+2018, U+2019, U+201A, and U+201B as single-quote delimiters, allowing an attacker-controll…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-17625] IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1…
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-17623] IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71284] Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_rest…
Fledge's backup-restore upload handler, upload_backup() (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's filename (tar_file_names[0]) and builds a shell command via string formatting: `cmd = "cp {} {}".format(source, backup_path); ret_code = os.system(cmd)`. The only pre-check on the filename is a prefix/suffix match (startswith(backup_prefix), endswith(v…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16022] @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functiona…
@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command without proper neutralization, allowing shell metacharacters to execute additional operating-system commands when the CLI…
M Alto vulnerabilidad
05/08/2026
Inyección de comandos alta en paquete npm backmeup (CVE-2026-71243)
El paquete backmeup para npm contiene una vulnerabilidad de inyección de comandos (CVSS 8.8) por concatenación insegura de strings en comandos shell. Un atacante puede ejecutar comandos arbitrarios localmente o vía SSH si la aplicación procesa entradas no validadas. Afecta a sistemas de respaldo automatizados y herramientas DevOps en empresas LATAM.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-70374] HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upl…
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-70375] HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deplo…
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), interpolating the configured branch value directly into a shell command with no escaping. GitDeployer.validate() only rejects a single-quote charact…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18900] A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file…
A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.
M Alto vulnerabilidad
04/08/2026
[CVE-2026-16793] An improper neutralization of special elements used in an operating system command vulnerability was…
An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker to execute arbitrary operating system commands as a privileged user under a specific circumstance.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/08/2026
Vulnerabilidad alta de inyección de comandos en Zyxel WAX650S (CVE-2026-6837)
Se ha identificado una vulnerabilidad de inyección de comandos posterior a autenticación en el programa CGI 'export-cgi' de los puntos de acceso inalámbrico Zyxel WAX650S en versiones hasta 7.10(ABRM.4)C0. Un administrador comprometido o usuario con privilegios elevados podría ejecutar comandos del sistema operativo en el dispositivo afectado. Esta vulnerabilidad impacta infraestructuras de conectividad corporativa, especialmente en entornos PYME en México y Latinoamérica que despliegan estos equipos como concentradores de red.
M Alto vulnerabilidad
03/08/2026
[CVE-2026-67599] ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows a…
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command substitution payloads into the filter parameter to execute arbitrary commands as the webcon…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-18641] A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to…
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be uti…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-69096] OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.…
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler build…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-67608] Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a…
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through…