Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87766] A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new ro…
A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-83999] Improper link resolution before file access ('link following') in Windows Resilient File System (ReF…
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81963] Improper link resolution before file access ('link following') in Windows Update Stack allows an aut…
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-70563] Improper link resolution before file access ('link following') in Windows Shell allows an unauthoriz…
Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69379] Improper link resolution before file access ('link following') in Windows NTFS allows an authorized …
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69289] Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows…
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-67368] Improper link resolution before file access ('link following') in SQL Server allows an authorized at…
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-78409] The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the conf…
The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.
M Alto vulnerabilidad
01/09/2026
[CVE-2024-14047] A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a dir…
A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated Winlogbeat operation to write to or delete arbitrary files. Successful exploitation could result in a denial of service.
M Alto vulnerabilidad
29/08/2026
[CVE-2026-82455] RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extrac…
RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can instead be written outside of it, breaking the extraction safety boundary. The fix resolves the real path of the parent…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55108] KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until…
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf …
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en gitoxide anterior a 0.52.1 permite inyección de metadatos de submódulos
gitoxide versiones anteriores a 0.52.1 presenta una vulnerabilidad que permite a atacantes seguir enlaces simbólicos en el archivo .gitmodules del árbol de trabajo, facilitando la inyección de bytes maliciosos en metadatos de submódulos. Un repositorio malicioso puede redirigir la lectura de configuración hacia archivos externos arbitrarios, exponiendo información controlada por el atacante en nombres, rutas y URLs de submódulos. Afecta principalmente a equipos de desarrollo que utilizan gitoxide para control de versiones en México y Latinoamérica.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81727] NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.…
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal pac…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81690] openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 ad…
openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory, while O_NOFOLLOW on the hash side binds only the final path component. An evil-maid attacker with physical access to the …
M Alto vulnerabilidad
27/08/2026
Vulnerabilidad de escalada de privilegios en CodeMeter Runtime (CVE-2026-81572)
La herramienta cmu.exe en CodeMeter Runtime crea archivos temporales predecibles sin validar reparse points de NTFS (junctions y symbolic links), permitiendo que un atacante local redirija operaciones de archivo hacia rutas arbitrarias del sistema. Dado que CodeMeter ejecuta con privilegios de Sistema, esta vulnerabilidad posibilita escalada de privilegios y comprometer servidores, bases de datos y aplicaciones altas en infraestructuras de LATAM que dependan de este software de protección de licencias.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-61792] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths without adequately confining them to the repository. This is an incomplete fix for CVE-2026-34242, whose original patch fai…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-66153] The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux…
The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79655] A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local a…
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the sy…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-72696] Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile()…
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a symlink at the predictable lock path pointing to any file the web server process can write to, and the next scheduled job run …
M Alto vulnerabilidad
21/08/2026
[CVE-2026-49114] In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the…
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attacker with write access to the directory where a victim serializes external data can deterministically pre-plant a symlink that is being followed, causi…