Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1014
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 20 horas
[CVE-2026-101024] Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its …
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary …
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-76454] A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Sm…
A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An att…
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost 5.8.0 a 6.33.x permite toma de control de cuentas administrativas
Ghost versiones 5.8.0 hasta 6.33.x contiene una falla de validación de entrada en el iframe administrativo que permite a atacantes con privilegios de publicación comprometer cuentas de personal mediante ingeniería social. Un usuario administrativo que visite una página maliciosa crafteada puede perder control de su cuenta, exponiendo configuraciones altas, contenido sensible y credenciales integradas en plataformas de contenido empresarial en LATAM.
M Crítico vulnerabilidad
29/09/2026
Vulnerabilidad crítica de traversal de directorios en Hitachi Energy RTU500 permite escritura de archivos arbitrarios
Una vulnerabilidad de traversal de directorios en la funcionalidad de carga de archivos del Hitachi Energy RTU500 permite a atacantes no autenticados escribir o sobrescribir archivos arbitrarios en el sistema de ficheros del dispositivo. La explotación exitosa podría resultar en modificación no autorizada de datos críticos de control o interrupción de operaciones en plantas de generación, subestaciones y sistemas de distribución de energía comúnmente desplegados en infraestructura LATAM.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93468] The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote att…
The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76424] A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload…
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and e…
M Crítico vulnerabilidad
14/09/2026
[CVE-2026-76440] As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Em…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82765] Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If th…
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82768] Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files …
Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
M Alto vulnerabilidad
14/09/2026
[CVE-2023-45858] A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to r…
A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89065] Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 m…
Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled generated file manifest that is consumed during project synthesis. To remediate this …
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-84939] Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can sp…
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache FreeMarker from 2.2.0 through 2.3.34. Users are recommended to upgrade to version 2.3.35. Disabling localized lookup in previ…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-15913] In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of For…
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-77897] Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locall…
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en SIMOVE Fleetmanager y SIPLANT afecta gestión de flotas
Se identificó una vulnerabilidad de validación en múltiples versiones de SIMOVE Fleetmanager (V3.1, V3.2, V3.3, V4.0) y SIPLANT (V1.7 a V3.1) con CVSS 8.6. Empresas de logística, transporte y distribución en LATAM que utilicen estas plataformas de gestión de flotas enfrentan riesgo de explotación remota. Se requiere actualización inmediata a versiones parcheadas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80130] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-80133] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-81849] Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in ama…
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary files outside the intended download directory with root privileges, via crafted object keys in the S3 source the document is…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81838] A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) …
A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to write arbitrary files to the local filesystem via crafted zip entry names containing path traversal sequences. This could allow the third party to perform inappropriate actions in the diagram bundle. To remediate this issue, users should up…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-66897] A path traversal vulnerability in LXD's instance template processing allows an attacker with contain…
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using …