Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Alto vulnerabilidad
11/08/2026
[CVE-2026-72713] XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-regis…
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an account without email verification, then submit crafted `file_name` values such as parent-directory tra…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48441] Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Pa…
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scop…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65768] Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams fo…
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48442] CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Director…
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is chang…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73079] Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product s…
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an operator-configured base URL) that belong to the operator, not to the caller. The `POST /responses/*sub…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-18640] The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user wit…
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.
M Alto vulnerabilidad
11/08/2026
Vulnerabilidad de path traversal en AsyncFuncAI deepwiki-open permite acceso no autenticado
Se reporta una vulnerabilidad de traversal de directorios (CVE-2026-72602, CVSS 7.5) en AsyncFuncAI deepwiki-open que permite a atacantes remotos sin autenticación enumerar la estructura de directorios del servidor a través del endpoint local-repository. El problema existe porque WIKI_AUTH_MODE está deshabilitado por defecto, exponiendo rutas arbitrarias del sistema de archivos. Empresas en LATAM que usen esta herramienta de wikis abiertas enfrentan riesgo de exposición de información sensible y reconocimiento del sistema.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-44763] SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient …
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the i…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-73030] unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_w…
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72903] Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious …
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary filename characters. In tabby-ssh/src/components/sftpPanel.component.ts, downloadFold…
M Alto vulnerabilidad
10/08/2026
[CVE-2026-69112] Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in…
Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial …
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72571] A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticat…
A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker to read arbitrary files from the server. The app.js handler at lines 151-153 passes the user-supplied req.body.dir parameter directly to res.sendFile() without sanitization, enabling directory traversal via absolute paths or ../ sequences to read sensitive system files.
M Alto vulnerabilidad
10/08/2026
[CVE-2026-72572] A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attac…
A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and download arbitrary files from the server. The lib/xapi.js file at lines 338 and 424 uses the user-controlled req.query.name parameter in path.join(cwd, name) without sanitization before passing it to res.download, enabling directory traversal via ../ sequences to access sensitive sys…
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16263] The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX ac…
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-49163] Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insigh…
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18427] @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. …
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18991] A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknow…
A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report b…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-18953] Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awsla…
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should upgrade to version 0.1.5 or later.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-8183] IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.1…
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-15979] The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable t…
The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through wp_strip_all_tags() (which does not strip path traversal sequences), is stored directl…