Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87088] Tanium addressed an unauthorized code execution vulnerability in Enforce.
Tanium addressed an unauthorized code execution vulnerability in Enforce.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81349] Improper neutralization of special elements used in an os command ('os command injection') in Azure …
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86733] Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/…
Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who uploads a crafted ZIP backup (POST /admin/backups/upload) and triggers a restore (POST …
M Alto vulnerabilidad
08/09/2026
[CVE-2026-61517] Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the…
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell commands as root by injecting into the IpAddr parameter. The parameter is interpolated directly into a shell command executed through system() with an incomplete denylist that only blocks spaces, pipes, semi…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-76561] A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificat…
A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achievi…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86540] knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project co…
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80127] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/09/2026
[CVE-2026-19843] A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch comm…
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the e…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-61409] Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Imprope…
Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-53932] laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1…
laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85656] An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.…
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85660] cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with…
cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation check.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85439] MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::…
MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the --dir parameter to execute arbitrary commands with the privileges of the operator running alogsplit.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85012] Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthe…
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the project to execute arbitrary commands in the blueprint resynthesis environment via shell metacharacters in the owner field of a [local] merge strategy entry…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-71963] Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulner…
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh wh…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2025-12737] The administrative operations within the Carbon Console do not adequately validate specific user-sup…
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta de inyección de comandos en Nuclio anterior a v1.17.4
Nuclio, framework serverless para procesamiento de eventos en tiempo real, contiene una vulnerabilidad de inyección de comandos del shell en versiones anteriores a 1.17.4. Un atacante remoto puede ejecutar comandos arbitrarios en el host Docker explotando la interpolación no validada del namespace en comandos docker ps. El riesgo es alta en entornos con autenticación deshabilitada (configuración por defecto).
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52831] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, ). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This iss…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84837] A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing th…
A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with t…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84838] A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to e…
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow…