Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27561] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/con…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted GET request with admin credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27562] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/con…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sending a crafted PUT request with admin credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
Inyección de comandos alta en endpoint /api/datastorage/data permite ejecución como root
Un atacante remoto con credenciales administrativas puede explotar una vulnerabilidad de inyección de comandos en el endpoint /api/datastorage/data enviando solicitudes GET manipuladas para ejecutar comandos con privilegios root en dispositivos afectados. Esta vulnerabilidad impacta infraestructuras altas en empresas LATAM que almacenan datos sensibles en dispositivos con esta interfaz expuesta.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27564] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastor…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-27565] An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell…
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27554] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/aja…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27558] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/att…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execution of commands with root privileges on the device.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27559] A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/da…
A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request with user credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27560] A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/d…
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted DELETE request with admin credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27547] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/aja…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27548] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/aja…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27549] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/att…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27550] A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_P…
A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using operator credentials allowing execution of commands with root privileges on the device.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-27551] A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/aja…
A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of commands with root privileges on the device.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-73447] A privileged attacker can exploit certain operation to execute arbitrary commands with root privileg…
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-86108] Insufficient validation of inputs supplied through affected VeloCloud Edge management and configurat…
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command execution with elevated privileges on the affected VeloCloud Edge.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-10144] Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arb…
Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to the server.open configuration on macOS. The openBrowser() function in packages/core/src/server/open.ts passes the URL through encodeURI() before interpolating it into a shell command executed via child_process.exec(), b…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-52484] An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to ex…
An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91853] A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is th…
A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation of the argument filetype leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91931] Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allo…
Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server.