Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1799
Esta semana
RSS
S Crítico vulnerabilidad
23/07/2026
[CVE-2026-65689] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full…
S Alto vulnerabilidad
23/07/2026
[CVE-2026-65690] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. The vulnerability is specific …
S Crítico vulnerabilidad
23/07/2026
[CVE-2026-65687] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full un…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-59542] Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Subscriber Arbitrary File Deletion in Kali Forms
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-59555] Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Unauthenticated Arbitrary File Deletion in Participants Database
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57696] Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
Contributor Arbitrary File Deletion in Picture Gallery
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65754] Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer…
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-65431] Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives ha…
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
F Alto vulnerabilidad
23/07/2026
[CVE-2026-15074] @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request …
@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segments before applying its own path-traversal guard, an unauthenticated attacker can bypass any route-sc…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-14985] The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation v…
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13186] In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-b…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-47731] The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS…
The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and CubeSat Missions. In versions prior to 2.6.1 and in version 3.1.0, the Binary Stream Capture (BSC) co…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-30633] Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc …
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50757] Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to e…
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server
M Alto vulnerabilidad
21/07/2026
[CVE-2026-30632] Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the c…
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-63454] An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln…
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-15724] In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated …
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-15789] A custom client can produce such an upload request to the BuildKit daemon that files can escape from…
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-15791] A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp…
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-64824] Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore fu…
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing outside the extraction directory. Because the official Docker image runs the Home Assis…