Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-104286] An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F…
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-55231] Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor…
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, a flawed central path sanitizer lets an authenticated admin-panel user who holds backup access (default role site_admin or higher) read and delete arbitrary files on a server. An attacker can recover database credentials from config/db.php, read host files such as /etc/…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-101888] The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability t…
The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the intended extraction directory during migration ZIP import. Attackers can craft ZIP entry names with traversal sequences processed by computeExtractionParameters() and resumableZipExtractor() in utilities/PrimeMoverSystemChe…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-95588] Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter
M Alto vulnerabilidad
01/10/2026
[CVE-2024-58388] Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclu…
Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply directory traversal sequences such as path=/manual/../../../ to access files outside the intended manual directory, inclu…
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta de path traversal en n8n permite acceso no autorizado a workflows y credenciales
n8n versiones anteriores a 1.123.80, de 2.0.0 antes de 2.39.6 y de 2.40.0 antes de 2.40.1 contienen una vulnerabilidad de path traversal que permite a atacantes redirigir llamadas API a recursos no autorizados. Esto expone workflows, ejecuciones y secretos de credenciales dentro del alcance de la clave API, representando un riesgo alta para automatizaciones en producción en empresas LATAM que dependen de n8n para integraciones de negocio.
M Crítico vulnerabilidad
01/10/2026
[CVE-2025-41753] The object name of a dynamically created BACnet File Object is interpreted as a file path without su…
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.