Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
F Crítico vulnerabilidad
25/06/2026
[CVE-2025-71336] Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote co…
Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and authorization model is minimal and lacks role-based access control, and the default installation runs without authentication unless…
C Crítico vulnerabilidad
25/06/2026
[CVE-2026-40079] Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vu…
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandl…
C Crítico vulnerabilidad
24/06/2026
[CVE-2026-39938] Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have u…
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.
R Crítico vulnerabilidad
24/06/2026
[CVE-2026-49980] Rclone is a command-line program to sync files and directories to and from different cloud storage p…
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute l…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12850] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12851] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12486] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
24/06/2026
[CVE-2026-12849] Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVisio…
Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability. `libNetSetObj.so` is an internal library used by various binaries on the device to configure the network stack (start and stop various servi…
F Crítico vulnerabilidad
23/06/2026
[CVE-2026-56274] Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server…
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can configure a malicious MCP server to bypass the validateCommandFlags blocklist (for ex…
S Crítico vulnerabilidad
17/06/2026
[CVE-2026-20266] In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute ar…
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation.
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-55743] The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (de…
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. Two flaws in src/openhuman/security/policy.rs combine: (1) is_args_safe() blocks the find flags -exec and -ok but not the functionally identical -execdir and -okdir, which also…
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-22313] The device has a webserver that exposes a REST API authenticated with a token on the management netw…
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38060] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlo…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38061] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38062] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38063] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radi…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38064] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38065] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.
F Crítico vulnerabilidad
15/06/2026
[CVE-2026-9862] Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in th…
Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
M Crítico vulnerabilidad
14/06/2026
[CVE-2026-11526] GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of…
GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument with Perl's 2-arg open(), so a filename that begins or ends with a pipe ("| cmd", "cmd |") or begins with a redirect ("> path", ">> path") is run as a command or redirect rather than opened as a file. _ma…