Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-74038] Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote…
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insufficient validation in OS_IsValidName() and unsafe path concatenation in delete_diff() to resolve the traversal to the parent queue directory, causing …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75914] CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool th…
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image extensions to leak file bytes to the vision endpoint without user approval.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75859] CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions fiel…
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can specify paths outside the workspace that are read and injected into the AI system prompt for exfiltration.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-73181] Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 ver…
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-48798] SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string…
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious, compromised, or man-in-the-middle server to use ../ sequences or absolute paths to c…
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad alta en ArcadeDB anterior a v26.8.1 permite manipulación de archivos del sistema
ArcadeDB versiones anteriores a 26.8.1 presentan falla de sanitización en el endpoint POST /api/v1/server que permite a usuarios autenticados con privilegios root escribir y eliminar archivos arbitrarios fuera del directorio configurado. Un atacante puede inyectar secuencias ../ en nombres de bases de datos para crear directorios en rutas del filesystem o ejecutar eliminaciones recursivas, comprometiendo la integridad de datos altas en infraestructuras de LATAM que usen esta base de datos NoSQL.
M Alto vulnerabilidad
Hace 6 días
Vulnerabilidad de lectura arbitraria de archivos en ArcadeDB anterior a versión 26.8.1
ArcadeDB en versiones anteriores a 26.8.1 contiene una vulnerabilidad que permite a usuarios autenticados leer archivos locales del servidor mediante la cláusula LOAD CSV FROM en OpenCypher, utilizando el protocolo file://. Atacantes con privilegios de lectura pueden exfiltrar datos sensibles directamente en respuestas de consultas, afectando sistemas de bases de datos en infraestructuras on-premise y en nube en LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-15585] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75111] Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoi…
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. Attackers can supply traversal sequences or absolute paths in the filename field to access system files, which are then materialized into datasets and retrieved through the download endpoint.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75482] SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that j…
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without rejecting parent-directory ('..') references, bypassing the built-in path sanitization. The server binds all interfaces (0.0.0.0), applies wildcard CORS, and requires no authentication. An unauthenticated network clie…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19589] Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow uni…
Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-57233] Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress functi…
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling plugin directory and execute attacker-controlled code when Notepad++ next loads that plugin. This issue is fixed in version…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-46345] compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 a…
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the iss…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-73646] PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rul…
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sources…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19693] extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and nev…
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16137] In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential…
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-16139] In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon…
In Progress ShareFile Storage Zones Controller versions
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74798] SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. …
SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path via filepath.Join without validating that id matches SiYuan's node-ID format. An authenticated MCP client can supply path t…
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica en plugin ProSolution WP Client permite eliminación arbitraria de archivos
El plugin ProSolution WP Client para WordPress (versiones ≤2.0.8) contiene una falla de validación de rutas que permite a atacantes no autenticados eliminar archivos arbitrarios del servidor. Esta vulnerabilidad puede ser explotada para ejecutar código remoto eliminando archivos críticos de WordPress, comprometiendo completamente el sitio web. Afecta directamente a pequeñas y medianas empresas en LATAM que utilizan este plugin en plataformas de comercio electrónico y gestión de contenidos.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-18855] The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f…
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). E…