Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81551] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrari…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81554] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain se…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-80424] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create ar…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88937] knowns through 0.33.0 fails to properly validate template destination paths in the code generation t…
knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite shell profiles, steal credentials, or achieve persistent code execution on victim systems.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81789] Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6…
Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64836] ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint du…
ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, which never succeeds, allowing authenticated attackers to submit traversal sequences or absolute paths in the file parameter to read, write, or delete files outside t…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-64838] ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and r…
ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequences in oldFileName to move files writable by the PHP process into the web-accessible project directory, disclosing file contents and deleting originals.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-9166] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS …
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-15019] The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all…
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloada…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86775] knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. …
knowns (npm package) versions
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86099] Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowin…
Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences. Attackers can craft malicious sessionId values that escape the upload directory and recursively delete arbitrary directories accessible to the service process.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-78485] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87023] Tanium addressed a path traversal vulnerability in Comply.
Tanium addressed a path traversal vulnerability in Comply.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87030] Tanium addressed a path traversal vulnerability in Comply.
Tanium addressed a path traversal vulnerability in Comply.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-53581] OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core …
OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape th…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77110] Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path …
Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does no…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-78461] Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code…
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69807] Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell…
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69445] Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed…
Improper limitation of a pathname to a restricted directory ('path traversal') in Windows Compressed Folder allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-74239] XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windo…
XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences in ZIP member names. Attackers can craft a malicious ZIP archive with backslash path separators tha…