Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76357] In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a craf…
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role for the request and does not restrict the user-supplied file path to the intended temporary directory. For more information…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-62680] Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specificat…
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Processing an attacker-controlled OpenAPI description can cause requests from the developer or CI host to attacker-selected or internal HTTP services, read absolute…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-49253] electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3…
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/zmodem.js, prepareReceiveFile() joins the filename to the user-selected save path, and in src/app/server/trzsz.js, getUniqueFilePath(), the openSaveFile() callback,…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-44829] Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling …
Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename containing Windows-style parent directory components survives sanitization. The original filename flows through ctx.diskToOriginal and the multi-output PDF routes i…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-15061] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote a…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-76222] GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers…
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during submodule initialization, creating attacker-controlled Git repositories at escaped fi…
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16616] The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-mov…
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, allowing them to read arbitrary files on the server and to relocate critical files out of the web root, leading to sensitive information disclosure and potential site takeover.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
19/08/2026
Vulnerabilidad alta en plugin Atarim para WordPress permite eliminación arbitraria de archivos
El plugin Atarim para WordPress (versiones hasta 5.1.1) contiene una falla de validación de rutas de archivo que permite a atacantes autenticados con nivel de autor eliminar archivos arbitrarios del servidor. Afecta principalmente a agencias digitales y estudios de diseño en LATAM que utilizan este plugin para gestión de contenido y feedback de clientes. La vulnerabilidad requiere acceso autenticado pero representa riesgo alta en entornos multiusuario.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-52872] Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle url using the file: URI scheme and passes its decoded pathname to fs.copyFileSync. The renderer also controls downloadPath, which determines the destinat…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-50186] 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an au…
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards/download.js, the decoded inputs.filename value is passed to path.join() beneath private/exports// without containment validation. A crafted val…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-74038] Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote…
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75914] CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool th…
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75859] CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions fiel…
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73181] Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 ver…
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-48798] SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string…
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to c…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad alta en ArcadeDB anterior a v26.8.1 permite manipulación de archivos del sistema
ArcadeDB versiones anteriores a 26.8.1 presentan falla de sanitización en el endpoint POST /api/v1/server que permite a usuarios autenticados con privilegios root escribir y eliminar archivos arbitrarios fuera del directorio configurado. Un atacante puede inyectar secuencias ../ en nombres de bases de datos para crear directorios en rutas del filesystem o ejecutar eliminaciones recursivas, comprometiendo la integridad de datos altas en infraestructuras de LATAM que usen esta base de datos NoSQL.
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad de lectura arbitraria de archivos en ArcadeDB anterior a versión 26.8.1
ArcadeDB en versiones anteriores a 26.8.1 contiene una vulnerabilidad que permite a usuarios autenticados leer archivos locales del servidor mediante la cláusula LOAD CSV FROM en OpenCypher, utilizando el protocolo file://. Atacantes con privilegios de lectura pueden exfiltrar datos sensibles directamente en respuestas de consultas, afectando sistemas de bases de datos en infraestructuras on-premise y en nube en LATAM.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-15585] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75111] Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoi…
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75482] SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that j…
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The server binds all interfaces (0.0.0.0), applies wildcard CORS, and requires no authentication. An unauthenticated network clie…