Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84085] IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due…
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84071] IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector p…
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-82892] IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to…
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81669] IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create c…
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81937] IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import r…
IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-82887] IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary c…
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81942] PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 an…
PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2025-14754] IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with el…
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
M Alto vulnerabilidad
17/09/2026
Inyección de comandos OS en Dell OpenManage Server Administrator anteriores a v11.1.0.3
Dell OpenManage Server Administrator en versiones previas a 11.1.0.3 contiene una vulnerabilidad de inyección de comandos OS (CVE-2026-81476, CVSS 8.1) que permite a atacantes remotos no autenticados ejecutar comandos arbitrarios en sistemas de administración de servidores. Esta vulnerabilidad afecta directamente infraestructuras altas en centros de datos de México y LATAM que dependen de esta herramienta para gestionar hardware Dell Enterprise.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92580] In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin…
In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escaping, so a single quote in the password breaks out of the quoted word and injects arbitrary shell. The password is writte…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-85756] SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplie…
SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an attacker-controlled path to a shell-based server, shell metacharacters not neutralize…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-71179] Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Sp…
Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27561] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/con…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27562] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/con…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
Inyección de comandos alta en endpoint /api/datastorage/data permite ejecución como root
Un atacante remoto con credenciales administrativas puede explotar una vulnerabilidad de inyección de comandos en el endpoint /api/datastorage/data enviando solicitudes GET manipuladas para ejecutar comandos con privilegios root en dispositivos afectados. Esta vulnerabilidad impacta infraestructuras altas en empresas LATAM que almacenan datos sensibles en dispositivos con esta interfaz expuesta.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27564] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastor…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27554] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/aja…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27558] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/att…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27559] A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/da…
A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27560] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/d…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.