Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 35 min
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-16335] IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacke…
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or delete arbitrary files due to a path traversal vulnerability.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-15955] IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an…
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82035] PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font…
PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators or dot-dot sequences. Attackers can supply a crafted PDF, EPUB, XPS, or FB2 file…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54178] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in src/app/Models/Traits/HasUploadFields.php trusts disk-relative paths from clear_[] and passes them to Storage::disk()->delete without confirming t…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-57145] PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py…
PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-controlled filepath parameter directly to open for reading and writing without traversal rejection, symlink resolution, a workspace boundary, or protected-path checks. Prompt-influenced agents can read files through edit and diff behavior or overwrite files accessible to the process,…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57119] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an ab…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing agent_file path in POST /api/v1/runs and passes it to the job executor without a workspace allowlist or boundary check. A remote caller can cause the server to open files accessible to the service account, exposing credentials, keys, environment variables, and other local data. …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-56839] PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_ro…
PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass workspace=None to read_file, search_replace, and apply_diff helpers that enforce path containment only for a truthy workspace. An application that exposes code_read_file, code_search_replace, or code_apply_diff before set_workspace can therefore let prompt-influenced calls read a…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82427] Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each b…
Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper force-deletes whatever already exists at the target before creating the link. A s…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82428] Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key…
Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in advance. When the blob already existed, the uploader caught `KeyAlreadyExistsException` and silently reused it, with no check that the existing blob's c…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-57129] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_fi…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspace-boundary validation. Prompt input from users, bots, or workflows can therefore read arbitrary files accessible to the process, including credentials, k…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-78299] In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS p…
In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.
M Alto vulnerabilidad
14/09/2026
Vulnerabilidad alta de path traversal en 0x4m4 HexStrike AI (CVE-2026-90691)
Se ha detectado una vulnerabilidad de path traversal en 0x4m4 HexStrike AI hasta la versión d689933ff579d839c676c82b231f8e98326c5f04. El defecto reside en la función FileOperationsManager del componente API Files Endpoint (hexstrike_server.py), permitiendo manipulación del parámetro filename. El exploit es de acceso remoto y ha sido divulgado públicamente, exponiendo servidores en LATAM que ejecuten versiones afectadas a acceso no autorizado a archivos del sistema.
M Alto vulnerabilidad
13/09/2026
Vulnerabilidad de traversal de directorios en rustypaste anterior a 0.18.1
rustypaste antes de la versión 0.18.1 contiene una vulnerabilidad que permite a atacantes eludir validaciones de ruta mediante secuencias de traversal en encabezados HTTP personalizados, posibilitando escritura de archivos en ubicaciones arbitrarias fuera del directorio configurado. Empresas en LATAM que usen este software de carga de archivos están expuestas a acceso no autorizado a sistemas de archivos e inyección de código malicioso. El impacto es alta en infraestructuras que procesan uploads de usuarios o integraciones automatizadas.
M Crítico vulnerabilidad
12/09/2026
Vulnerabilidad crítica en GitLab CE/EE permite lectura no autenticada de archivos arbitrarios
GitLab ha remediado una vulnerabilidad que afecta versiones 18.7, 19.1 antes de 19.1.8, 19.2 antes de 19.2.6 y 19.3 antes de 19.3.2. Un usuario no autenticado puede leer archivos arbitrarios del servidor GitLab explotando falta de confinamiento de rutas y validación de autenticación en la API de commits del repositorio. Este riesgo es crítico (CVSS 10.0) para empresas en LATAM que usan GitLab para control de versión y CI/CD.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de traversal de directorios en libks anteriores a v2.0.11
libks, biblioteca fundamental para productos SignalWire C, contiene un defecto en la función `clean_uri()` del analizador HTTP que permite eludir la validación de rutas. Versiones anteriores a 2.0.11 no rechazarán URIs con segmentos de ruta excesivos, dejando secuencias ".." intactas y facilitando ataques de traversal de directorios. Esto afecta a cualquier aplicación que integre libks y procese solicitudes HTTP, comprometiendo el acceso a archivos sensibles en servidores de telecomunicaciones y plataformas de comunicaciones unificadas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-19991] The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and inc…
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-77807] The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugi…
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-82100] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a d…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84889] IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81540] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.