Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,971
Total alertas
3188
Críticas
10511
Altas
8
Ransomware
1038
Esta semana
RSS
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8665] OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Lin…
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8666] OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plug…
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.
R Alto vulnerabilidad
25/06/2026
[CVE-2026-8592] OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin …
OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.
G Alto vulnerabilidad
25/06/2026
[CVE-2026-9154] Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated…
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.
G Alto vulnerabilidad
25/06/2026
[CVE-2026-9155] OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated…
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.
O Alto vulnerabilidad
25/06/2026
[CVE-2026-57589] sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation …
sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9780] Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vuln…
Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the addclient3 webpage. …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9781] Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerab…
Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBURASDevice JSON-…
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9782] Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulner…
Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBUDeviceDrive J…
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9783] Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vul…
Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBURemovableM…
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9784] Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulner…
Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULibraryPort J…
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9785] Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulner…
Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULibrarySlot J…
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9786] Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerab…
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBUDashboard JSON-…
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-9787] Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vuln…
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULogDaemon J…
C Alto vulnerabilidad
25/06/2026
[CVE-2026-39951] Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a…
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
C Crítico vulnerabilidad
25/06/2026
[CVE-2026-40079] Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vu…
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by rrdtool_function_graph() is passed through this function and then to shell_exec($full_commandl…
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-7569] Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vuln…
Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVault Backup. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the viewclient webpage. …
Q Alto vulnerabilidad
25/06/2026
[CVE-2026-7570] Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerab…
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBUDashboard JSON-…
G Alto vulnerabilidad
24/06/2026
[CVE-2025-60474] A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box…
A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
C Crítico vulnerabilidad
24/06/2026
[CVE-2026-39938] Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have u…
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31.