Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de Path Traversal en gitoxide (gix ≤ 0.72.0 y gix-validate ≤ 0.10.0)
gitoxide, conjunto de herramientas Rust para gestión de repositorios Git, contiene una vulnerabilidad de path traversal (CVSS 7.5) en la validación de nombres de submódulos. La función de validación solo verifica la primera ocurrencia de '..', permitiendo nombres manipulados como 'a..b/../../../.git/' eludir el control. Esta validación tampoco se ejecuta en rutas de código de producción, exponiendo sistemas que procesan repositorios Git no confiables a acceso no autorizado de archivos.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de traversal de ruta en gitoxide anterior a 0.52.1 mediante validación deficiente de submódulos
gitoxide versiones anteriores a 0.52.1 no valida correctamente nombres de submódulos en configuración .gitmodules, permitiendo ataques de traversal de ruta que redirigen operaciones hacia repositorios fuera del directorio .git/modules. Atacantes pueden inyectar submódulos maliciosos para provocar confusión de repositorio e inspección de código controlado por el adversario, afectando integridad de repositorios en empresas que utilizan esta librería en LATAM.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-61800] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-75337] The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to pa…
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attackers to read files outside the preview root.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54083] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the  srcip  field taken from alert JSON directly onto the fixed  /ip…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81730] Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message…
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to file_put_contents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollecto…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-76639] Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerabilit…
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-47884] Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has…
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and ea…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81491] A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_…
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has no…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-61792] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths without adequately confining them to the repository. This is an incomplete fix for CVE-2026-34242, whose original patch fai…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-54550] IzPack is a widely used tool for packaging applications on the Java platform as cross-platform insta…
IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.java obtains an attacker-controlled PackFile targetPath, passes it through IoHelper.translatePath(), which only converts separators, and constructs a File without n…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-15990] The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up t…
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires Formidable Forms Lite, Formidable Forms Pro, and Formidable Cha…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-75797] The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it …
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-57171] Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc…
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without path-traversal validation, allowing arbitrary file write outside the Trestle workspace. …
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de traversal de directorios en DB-GPT permite ejecución de código remoto
DB-GPT construye rutas de destino para habilidades cargadas usando nombres de archivo sin validación, permitiendo ataques de traversal de directorios. Un atacante puede escribir archivos fuera del directorio designado e inyectar código malicioso. Afecta infraestructuras de IA/ML en empresas mexicanas y latinoamericanas que utilizan esta plataforma para procesamiento de datos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de traversal de ruta en NVIDIA OpenShell Sandbox para Linux (CVE-2026-65092)
NVIDIA OpenShell Sandbox para Linux contiene una vulnerabilidad que permite a atacantes eludir la política de seguridad de red L7 REST mediante traversal de ruta, facilitando acceso no autorizado a información sensible y manipulación de datos. Esta falla afecta infraestructuras de contenedorización y edge computing en datacenters de LATAM que dependen de OpenShell para aislamiento de cargas de trabajo.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55540] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses …
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other code tools to access files outside the configured workspace. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55527] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable locations. The fix sanitizes user_id before constructing self.user_path. This issue is fixed in version 1.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79622] A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the …
A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. T…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-57863] Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that all…
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry names passed to PHP's ZipArchive::extractTo() to write arbitrary PHP files into …