Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-101024] Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its …
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary …
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost 5.8.0 a 6.33.x permite toma de control de cuentas administrativas
Ghost versiones 5.8.0 hasta 6.33.x contiene una falla de validación de entrada en el iframe administrativo que permite a atacantes con privilegios de publicación comprometer cuentas de personal mediante ingeniería social. Un usuario administrativo que visite una página maliciosa crafteada puede perder control de su cuenta, exponiendo configuraciones altas, contenido sensible y credenciales integradas en plataformas de contenido empresarial en LATAM.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93468] The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote att…
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76424] A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload…
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and e…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82765] Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If th…
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82768] Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files …
Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
M Alto vulnerabilidad
14/09/2026
[CVE-2023-45858] A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to r…
A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89065] Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 m…
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis. To remediate this …
M Alto vulnerabilidad
09/09/2026
[CVE-2026-15913] In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of For…
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77897] Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locall…
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en SIMOVE Fleetmanager y SIPLANT afecta gestión de flotas
Se identificó una vulnerabilidad de validación en múltiples versiones de SIMOVE Fleetmanager (V3.1, V3.2, V3.3, V4.0) y SIPLANT (V1.7 a V3.1) con CVSS 8.6. Empresas de logística, transporte y distribución en LATAM que utilicen estas plataformas de gestión de flotas enfrentan riesgo de explotación remota. Se requiere actualización inmediata a versiones parcheadas.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80130] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80133] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-81849] Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in ama…
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary files outside the intended download directory with root privileges, via crafted object keys in the S3 source the document is…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81838] A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) …
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle. To remediate this issue, users should up…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78212] 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. U…
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
M Alto vulnerabilidad
21/08/2026
Vulnerabilidad alta de traversal de directorios en LeafWiki versiones 0.3.0 a 0.10.0
LeafWiki, plataforma wiki autohospedada, contiene una vulnerabilidad de traversal de directorios (CVSS 8.8) en la funcionalidad de renombrado de activos que afecta versiones 0.3.0 a 0.10.0. Un usuario autenticado con permisos de editor puede mover archivos accesibles al proceso del servidor hacia directorios de activos, exponiendo archivos sensibles como bases de datos de aplicaciones para descarga. Esto representa riesgo alta para organizaciones en LATAM que utilizan LeafWiki en entornos corporativos con datos sensibles.
M Alto vulnerabilidad
20/08/2026
[CVE-2026-63490] Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.g…
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based loaders. In handlebars-springmvc/src/main/java/com/github/jknack/handlebars/springmvc/SpringTemplate…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72677] Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources…
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70337] Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code…
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.