Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
18/08/2026
[CVE-2026-50186] 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an au…
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards/download.js, the decoded inputs.filename value is passed to path.join() beneath private/exports// without containment validation. A crafted val…
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-47627] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-74038] Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote…
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75914] CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool th…
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75859] CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions fiel…
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73181] Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 ver…
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-48798] SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string…
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to c…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad alta en ArcadeDB anterior a v26.8.1 permite manipulación de archivos del sistema
ArcadeDB versiones anteriores a 26.8.1 presentan falla de sanitización en el endpoint POST /api/v1/server que permite a usuarios autenticados con privilegios root escribir y eliminar archivos arbitrarios fuera del directorio configurado. Un atacante puede inyectar secuencias ../ en nombres de bases de datos para crear directorios en rutas del filesystem o ejecutar eliminaciones recursivas, comprometiendo la integridad de datos altas en infraestructuras de LATAM que usen esta base de datos NoSQL.
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad de lectura arbitraria de archivos en ArcadeDB anterior a versión 26.8.1
ArcadeDB en versiones anteriores a 26.8.1 contiene una vulnerabilidad que permite a usuarios autenticados leer archivos locales del servidor mediante la cláusula LOAD CSV FROM en OpenCypher, utilizando el protocolo file://. Atacantes con privilegios de lectura pueden exfiltrar datos sensibles directamente en respuestas de consultas, afectando sistemas de bases de datos en infraestructuras on-premise y en nube en LATAM.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-15585] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75111] Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoi…
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75482] SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that j…
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The server binds all interfaces (0.0.0.0), applies wildcard CORS, and requires no authentication. An unauthenticated network clie…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19589] Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow uni…
Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-57233] Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress functi…
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling plugin directory and execute attacker-controlled code when Notepad++ next loads that plugin. This issue is fixed in version…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-46345] compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 a…
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the iss…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-73646] PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul…
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sources…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19693] extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and nev…
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16137] In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential…
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16139] In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon…
In Progress ShareFile Storage Zones Controller versions
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74798] SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. …
SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path via filepath.Join without validating that id matches SiYuan's node-ID format. An authenticated MCP client can supply path t…