Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Crítico vulnerabilidad
21/09/2026
[CVE-2026-77521] MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a …
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_…
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-93958] A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst…
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-80442] IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerabili…
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the confidentiality, integrity, and availability of the affected system.
M Crítico vulnerabilidad
17/09/2026
Vulnerabilidad crítica de inyección de comandos en appliances FatPipe MPVPN, WARP e IPVPN
Los equipos FatPipe MPVPN, WARP e IPVPN con firmware 10.1.2r60p100 (fin de vida) contienen una vulnerabilidad de inyección de comandos OS en el demonio xtremed. Un atacante remoto no autenticado puede enviar entrada manipulada al endpoint AuthFormServlet para ejecutar comandos arbitrarios en el sistema, afectando la integridad de infraestructuras VPN críticas en empresas latinoamericanas. El CVSS de 9.8 refleja el riesgo extremo sin requerir autenticación previa.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92398] A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unk…
A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20305] A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remot…
A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker coul…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-20306] A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attack…
A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit thi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92397] A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerabilit…
A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27565] An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell…
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-73447] A privileged attacker can exploit certain operation to execute arbitrary commands with root privileg…
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-55158] Conflibot warns in advance when merging a pull request will cause conflicts in other open pull reque…
Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings passed to exec. In the documented pull_request_target configuration, an attacker can open a pull request, including from a…
M Crítico vulnerabilidad
15/09/2026
[CVE-2026-90847] A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown functio…
A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57124] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose PO…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect without mandatory authentication and accept caller-controlled command and args values that PraisonAIUI passes to StdioMCPClient to start a local process. Because the UI commands bind to 0.0.0.0 by default, a reachable unauthenticated client can execute commands as the UI service …
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 1.1.52 permite ejecución remota
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 versión 1.1.52 que permite inyección de comandos del sistema operativo a través de la función /boafrm/formDiskFormat. Un atacante remoto puede manipular el parámetro 'partition' para ejecutar comandos arbitrarios sin autenticación. El exploit está publicado y activamente en uso.
M Crítico vulnerabilidad
14/09/2026
Inyección de comandos OS en D-Link DWR-M921 versión 1.1.52 (CVE-2026-90703)
Se ha identificado una vulnerabilidad crítica (CVSS 9.1) en el router D-Link DWR-M921 1.1.52 que permite inyección de comandos del sistema operativo a través del parámetro folderpath en la función de creación de comparticiones de disco. El ataque es remotamente exploitable y el exploit público ya circula en la comunidad de seguridad. Esta vulnerabilidad afecta principalmente a PyMES y empresas en LATAM que utilizan estos equipos como gateways de red.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en D-Link DWR-M920 1.1.7 permite inyección de comandos OS
Se identificó una debilidad en el enrutador D-Link DWR-M920 versión 1.1.7 que permite inyección de comandos del sistema operativo a través del parámetro newPin en la función /boafrm/formPinManageSetup. El ataque puede ejecutarse remotamente sin autenticación y el exploit ya está disponible públicamente. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan este modelo para conectividad de sucursales.
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-89010] WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticat…
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string vi…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-79724] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81467] Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elem…
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81468] Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elem…
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.