Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-78212] 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. U…
4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.
M Alto vulnerabilidad
Hace 2 días
Vulnerabilidad alta de traversal de directorios en LeafWiki versiones 0.3.0 a 0.10.0
LeafWiki, plataforma wiki autohospedada, contiene una vulnerabilidad de traversal de directorios (CVSS 8.8) en la funcionalidad de renombrado de activos que afecta versiones 0.3.0 a 0.10.0. Un usuario autenticado con permisos de editor puede mover archivos accesibles al proceso del servidor hacia directorios de activos, exponiendo archivos sensibles como bases de datos de aplicaciones para descarga. Esto representa riesgo alta para organizaciones en LATAM que utilizan LeafWiki en entornos corporativos con datos sensibles.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-63490] Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.g…
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation used by other URL-based loaders. In handlebars-springmvc/src/main/java/com/github/jknack/handlebars/springmvc/SpringTemplate…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72677] Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources…
Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fleet Server host configuration without rejecting relative traversal sequences. The identifier is stored as provided and is later incorporated into the request that Kibana issues when that configuration …
M Alto vulnerabilidad
11/08/2026
[CVE-2026-70337] Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code…
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-65810] Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges loca…
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
M Alto vulnerabilidad
11/08/2026
[CVE-2026-53416] Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information…
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/08/2026
[CVE-2026-16053] Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to A…
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
M Alto vulnerabilidad
09/08/2026
Vulnerabilidad alta de traversal de directorios en LOLLMS 2.1.0 permite acceso no autorizado
LOLLMS versión 2.1.0 contiene una vulnerabilidad de traversal de rutas en su módulo de interfaz (SPA catch-all route) que permite a atacantes eludir controles de seguridad mediante secuencias codificadas en URL (%2e%2e) y acceder a archivos fuera del directorio permitido. Este fallo afecta directamente a servidores de IA/ML en empresas LATAM que despliegan esta solución sin actualizar. La vulnerabilidad tiene puntuación CVSS 7.5 (Alta) y requiere atención inmediata en entornos de producción.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-15802] The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient …
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution …
M Alto vulnerabilidad
20/07/2026
[CVE-2026-54910] FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the…
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors. The primary vector is the `path` parameter: it is passed d…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-56196] Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a…
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50454] Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate priv…
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-50663] Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacke…
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-40400] Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a n…
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-14903] Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker t…
Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-50181] Langroid is a framework for building large-language-model-powered applications. Prior to version 0.6…
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operations. However, the tools only change the process working directory to `curr_dir` and then operate on the user-supplied `file_path` without resolving and enforcing t…
M Alto vulnerabilidad
09/07/2026
[CVE-2026-59832] SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepa…
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks, allowing an authenticated request such as /snippets/%2e%2e/%2e%2e/conf/conf.json to read workspace secrets and the document d…
M Alto vulnerabilidad
09/07/2026
[CVE-2026-61343] LibreBooking's email template editor save action passes the submitted template name directly into th…
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.
M Alto vulnerabilidad
07/07/2026
[CVE-2026-14476] A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() funct…
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to auth…