Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
07/09/2026
[CVE-2026-86542] knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated a…
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86439] knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing atta…
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86538] knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/prev…
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86541] knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() func…
knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-6377] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80131] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-81939] A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and arc…
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19303] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrar…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19306] IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from …
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file content…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85685] AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill t…
AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request parameter to copy files into the skills directory, making them accessible through the workspace skill listing.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85690] Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attacke…
Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model output through poisoned repository files or attacker-controlled context to write to arbitrary locations like shell rc or cron files, achieving code execution.
M Crítico vulnerabilidad
04/09/2026
[CVE-2026-85661] excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unse…
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85606] firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_par…
firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and environment variables, which are then uploaded and returned to the model context.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85396] rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fail…
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85124] @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash …
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escap…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84667] Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration thr…
Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system in backups.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84669] A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Ite…
A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84671] Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary loca…
Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78590] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kiban…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause a subsequent administrative action to act on unintended internal resources, resulting in the deletion of privileged reso…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18672] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied s…
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outside the intended image directories.