Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
A Alto vulnerabilidad
27/07/2026
[CVE-2026-43749] A parsing issue in the handling of directory paths was addressed with improved path validation. This…
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
A Alto vulnerabilidad
27/07/2026
[CVE-2026-43723] A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iP…
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.
J Alto vulnerabilidad
27/07/2026
[CVE-2026-65921] A path validation weakness in archive extraction/write handling allows entries with traversal sequen…
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-45623] PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul…
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS in…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66050] NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer se…
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to a…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65694] Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller …
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive file…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65919] Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/syst…
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65702] Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persi…
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from outside the intended store base directory. Attackers can supply path traversal sequences in the conversation_id parameter subm…
S Alto vulnerabilidad
23/07/2026
[CVE-2026-65690] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. The vulnerability is specific …
M Alto vulnerabilidad
23/07/2026
[CVE-2026-59542] Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Subscriber Arbitrary File Deletion in Kali Forms
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57696] Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
Contributor Arbitrary File Deletion in Picture Gallery
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65754] Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer…
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
F Alto vulnerabilidad
23/07/2026
[CVE-2026-15074] @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request …
@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segments before applying its own path-traversal guard, an unauthenticated attacker can bypass any route-sc…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-14985] The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation v…
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13186] In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-b…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-30633] Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc …
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50757] Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to e…
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server
M Alto vulnerabilidad
21/07/2026
[CVE-2026-30632] Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the c…
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-63454] An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln…
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-15724] In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated …
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.