Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 4143 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en D-Link DWR-M920 1.1.7 permite inyección de comandos OS
Se identificó una debilidad en el enrutador D-Link DWR-M920 versión 1.1.7 que permite inyección de comandos del sistema operativo a través del parámetro newPin en la función /boafrm/formPinManageSetup. El ataque puede ejecutarse remotamente sin autenticación y el exploit ya está disponible públicamente. Afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan este modelo para conectividad de sucursales.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en D-Link DIR-878 120B05 permite desbordamiento de búfer remoto
Se ha identificado un fallo de seguridad crítico (CVSS 9.9) en el enrutador D-Link DIR-878 versión 120B05 que afecta la función SetWan3Settings. Un atacante remoto puede explotar un desbordamiento de búfer en la pila manipulando los parámetros de DNS primario/secundario, comprometiendo completamente dispositivos expuestos en redes corporativas y pequeña empresa de México y LATAM.
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta de path traversal en 0x4m4 HexStrike AI (CVE-2026-90691)
Se ha detectado una vulnerabilidad de path traversal en 0x4m4 HexStrike AI hasta la versión d689933ff579d839c676c82b231f8e98326c5f04. El defecto reside en la función FileOperationsManager del componente API Files Endpoint (hexstrike_server.py), permitiendo manipulación del parámetro filename. El exploit es de acceso remoto y ha sido divulgado públicamente, exponiendo servidores en LATAM que ejecuten versiones afectadas a acceso no autorizado a archivos del sistema.
M Crítico vulnerabilidad
14/09/2026
Vulnerabilidad crítica en router D-Link DIR-878 120B05 permite desbordamiento de pila remoto
Se detectó una vulnerabilidad crítica (CVSS 9.9) en el router D-Link DIR-878 versión 120B05 que afecta la función SetDynamicDNSIPv6Settings. Un atacante remoto puede explotar esta falla manipulando los parámetros IPv6Address/Hostname para provocar un desbordamiento de pila (stack-based buffer overflow), potencialmente logrando ejecución remota de código. Este router es ampliamente utilizado en pequeñas y medianas empresas (PyMES) en México y LATAM para conectividad WAN.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90689] A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the fun…
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90690] A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.…
A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a manipulation of the argument additional_args/target/username/password/scan_type/payload can lead to os command injection. The attack can be launched remotely. The e…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82791] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82793] Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wirele…
Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82794] SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vu…
SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-82787] Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerabil…
Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82789] An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exis…
An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82777] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82779] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82780] Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially …
Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82770] Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specia…
Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82772] Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially…
Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82774] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82762] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82765] Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If th…
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82766] Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exi…
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.