2026年8月3日月曜日

3日 月曜日、友引

+ RHSA-2026:49524 Important: perl-Archive-Tar security update
https://access.redhat.com/errata/RHSA-2026:49524
CVE-2026-9538

+ RHSA-2026:49511 Important: frr security update
https://access.redhat.com/errata/RHSA-2026:49511
CVE-2026-37460

+ RHSA-2026:49214 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:49214
CVE-2026-31692
CVE-2026-43116
CVE-2026-46150
CVE-2026-64530

+ RHSA-2026:49525 Important: perl-Archive-Tar security update
https://access.redhat.com/errata/RHSA-2026:49525
CVE-2026-9538

+ RHSA-2026:49212 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:49212
CVE-2026-52923
CVE-2026-52993
CVE-2026-64530

+ Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit
https://cxsecurity.com/issue/WLB-2026080002
CVE-2026-46215

VU#243636 VPS.org one-click deployment templates contain multiple vulnerabilities
https://www.kb.cert.org/vuls/id/243636

JVNVU#98879231 三菱電機製複数製品で使用しているCC-Link IE TSN通信プロトコルにおける通信チャネルで送受信するメッセージに対する完全性の検証不備に起因する脆弱性
https://jvn.jp/vu/JVNVU98879231/index.html

JVN#72334274 サイボウズ Garoonにおけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN72334274/index.html

JVNVU#91736352 VPS.orgのone-click deploymentテンプレートにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91736352/index.html

JVNVU#92540957 シャープ製ネットワークスキャナーツールの初期設定がセキュアでない問題
https://jvn.jp/vu/JVNVU92540957/index.html

JVNVU#98759887 シャープ製および東芝テック製複合機(MFP)における複数の脆弱性
https://jvn.jp/vu/JVNVU98759887/index.html

JVNVU#97496464 CISA ICS Advisory / ICS Medical Advisory(2026年07月30日)
https://jvn.jp/vu/JVNVU97496464/index.html

JVNVU#90278463 SGLangにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90278463/index.html

JVNVU#92804348 ロボット掃除機DEEBOT PRO M1、DEEBOT PRO K1VACおよびスマートフォンアプリECOVACS PROにおける複数の脆弱性
https://jvn.jp/vu/JVNVU92804348/index.html

JVNVU#94952030 BaserCMSにおけるCSVファイルインジェクションの脆弱性
https://jvn.jp/vu/JVNVU94952030/index.html

キーワード
Shadow AI(シャドーAI)
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600009/072800228/?ST=nxt_thmit_security

フォーカス
AIエージェントのリスク ID管理とログで統制
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600014/072800233/?ST=nxt_thmit_security

日経コンピュータ「動かないコンピュータ」
デジタル庁などが仕様に疑義 マイナ署名関連の一部機能を停止
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/072800212/?ST=nxt_thmit_security

ニュース解説
AnthropicのAIも他社侵入、しかも3件 設定ミスでネットアクセス可能に
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11940/?ST=nxt_thmit_security

2026年7月31日金曜日

31日 金曜日、大安

+ RHSA-2026:48790 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:48790
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283
CVE-2026-33186
CVE-2026-34986

+ RHSA-2026:48703 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:48703
CVE-2026-55693
CVE-2026-57455
CVE-2026-57456
CVE-2026-59858

+ RHSA-2026:48197 Low: php:8.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:48197
CVE-2026-14355

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ PHP 8.4.24, 8.3.33 released
https://www.php.net/ChangeLog-8.php#8.4.24
https://www.php.net/ChangeLog-8.php#8.3.33

VU#281278 SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure
https://www.kb.cert.org/vuls/id/281278

VU#790363 foreUP golf management platform's web API contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/790363

JVNVU#91587639 Develar製app-builder(zipx.Unzip)における任意のファイルが上書きされる脆弱性
https://jvn.jp/vu/JVNVU91587639/index.html

JVNVU#98815601 トレンドマイクロ製TrendAI Vision Oneに対するセキュリティアップデート(2026年7月)
https://jvn.jp/vu/JVNVU98815601/index.html

月刊ランサムリポート
2026年5月の被害件数は876件で減少傾向 NightSpireは「Mimikatz」悪用して攻撃
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/071600018/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIによる「ランサムウエア攻撃」 侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/072300191/?ST=nxt_thmit_security

どうするSCS評価制度 第2回
SCS評価制度で「チェックシート地獄」は解消できるか、今取り組める2点
https://xtech.nikkei.com/atcl/nxt/column/18/03702/072800001/?ST=nxt_thmit_security

月刊ランサムリポート 第20回
ランサムグループ「INC」の存在感が強まる、Citrix Bleedを悪用
https://xtech.nikkei.com/atcl/nxt/column/18/03053/072900021/?ST=nxt_thmit_security

ニュース解説
GPT「暴走」にMicrosoftナデラCEOが言及、単一モデルへの依存に警鐘
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11933/?ST=nxt_thmit_security

2026年7月30日木曜日

30日 木曜日、仏滅

+ Gpg4win 5.1.0 released
https://www.gpg4win.org/change-history.html

+ RHSA-2026:48225 Important: perl:5.32 security update
https://access.redhat.com/errata/RHSA-2026:48225
CVE-2026-9538

+ RHSA-2026:47998 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2026:47998
CVE-2026-64600

+ RHSA-2026:47750 Low: php:7.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:47750
CVE-2026-14355

+ RHSA-2026:47749 Low: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:47749
CVE-2026-14355

+ RHSA-2026:47731 Important: gstreamer1-plugins-bad-free security update
https://access.redhat.com/errata/RHSA-2026:47731
CVE-2026-59691
CVE-2026-59692

+ RHSA-2026:47981 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2026:47981
CVE-2026-64600

+ Google Chrome 151.0.7922.71/.72 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html

+ Zabbix 7.4.13 released
https://www.zabbix.com/rn/rn7.4.13

+ FreeBSD-SA-26:55.elf  Race condition in ELF core dump segment counting
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:55.elf.asc
CVE-2026-58088

+ FreeBSD-SA-26:54.sysvsem Heap out-of-bounds access in semctl(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:54.sysvsem.asc
CVE-2026-58087

+ FreeBSD-SA-26:53.ktrace ktrace(2) privilege incorrectly validated in jails
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:53.ktrace.asc
CVE-2026-58086

+ FreeBSD-SA-26:52.if_wg Missing MAC validation in wg(4) packet decryption
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:52.if_wg.asc
CVE-2026-58085

+ FreeBSD-SA-26:51.ktimer Kernel stack disclosure via timer_settime(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:51.ktimer.asc
CVE-2026-58084

+ FreeBSD-SA-26:50.kqueue Use-after-free in kqueue copy-on-fork
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:50.kqueue.asc
CVE-2026-58083

+ JVNVU#99139115 Apache TomcatのWebSocket chatサンプルにおけるサービス運用妨害(DoS)の脆弱性(2026年7月28日)
https://jvn.jp/vu/JVNVU99139115/index.html
CVE-2026-66299

VU#293714 Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)
https://www.kb.cert.org/vuls/id/293714

VU#305509 OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure
https://www.kb.cert.org/vuls/id/305509

変貌するCDN 第4回
CDNを使うにはDNSから設定する、キャッシュからの情報流出に要注意
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200004/?ST=nxt_thmit_security

どうするSCS評価制度
経産省などが注意喚起、SCS評価制度の開始前に起きた不適切な勧誘
https://xtech.nikkei.com/atcl/nxt/column/18/03702/072800002/?ST=nxt_thmit_security

ニュース解説
AI攻撃にAIで対抗、Microsoftが新システム サイバー防御の独自モデルも
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11930/?ST=nxt_thmit_security

JVN#99975039 てがろぐ -Fumy Otegaru Memo Logger-における制限が不十分な正規表現を使用している脆弱性
https://jvn.jp/jp/JVN99975039/index.html

2026年7月29日水曜日

29日 水曜日、先負

+ ■Knot Resolverの脆弱性情報が公開されました
https://jprs.jp/tech/security/2026-07-28-knotresolver.html

+ RHSA-2026:47105 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:47105
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16351
CVE-2026-16352
CVE-2026-16353
CVE-2026-16354
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16358
CVE-2026-16359
CVE-2026-16360
CVE-2026-16361
CVE-2026-16362
CVE-2026-16363
CVE-2026-16368
CVE-2026-16369
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412
CVE-2026-56208

+ RHSA-2026:47060 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:47060
CVE-2026-13149
CVE-2026-59873
CVE-2026-59874

+ RHSA-2026:47011 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:47011
CVE-2026-53006

+ RHSA-2026:46990 Important: sssd security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:46990
CVE-2026-14474
CVE-2026-14476

+ Google Chrome 150.0.7871.212 released
https://chromereleases.googleblog.com/2026/07/extended-stable-updates-for-desktop.html

+ Mozilla Firefox 153.0.1 released
https://www.firefox.com/en-US/firefox/153.0.1/releasenotes/

+ Zabbix 7.0.29, 6.0.48 released
https://www.zabbix.com/rn/rn7.0.29
https://www.zabbix.com/rn/rn6.0.48

VU#141367 AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface
https://www.kb.cert.org/vuls/id/141367

変貌するCDN 第3回
セキュリティーからエッジAIまで、「仲介」機能を生かして拡大するCDN
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200003/?ST=nxt_thmit_security

UPDATE: JVN#03037325 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年5月)
https://jvn.jp/jp/JVN03037325/index.html

JVN#24885537 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性
https://jvn.jp/jp/JVN24885537/index.html

JVN#56870912 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年7月)
https://jvn.jp/jp/JVN56870912/index.html

2026年7月28日火曜日

28日 火曜日、友引

+ ■PowerDNS Recursorの脆弱性情報が公開されました(CVE-2026-52688、CVE-2026-52686)
https://jprs.jp/tech/security/2026-07-27-powerdns-recursor.html

+ About the security content of iOS 26.6 and iPadOS 26.6
https://support.apple.com/en-us/128066
CVE-2026-64733
CVE-2026-43801
CVE-2026-28928
CVE-2026-43776
CVE-2026-64725
CVE-2026-43730
CVE-2026-64747
CVE-2026-64707
CVE-2026-43811
CVE-2026-43813
CVE-2026-64746
CVE-2026-64734
CVE-2026-43797
CVE-2026-43673
CVE-2026-43744
CVE-2026-43803
CVE-2026-43711
CVE-2026-3784
CVE-2026-3783
CVE-2026-43753
CVE-2026-43714
CVE-2026-64742
CVE-2026-64740
CVE-2026-43796
CVE-2026-64692
CVE-2026-43780
CVE-2026-43818
CVE-2026-64716
CVE-2026-64758
CVE-2026-64754
CVE-2026-64693
CVE-2026-43805
CVE-2026-64749
CVE-2026-43778
CVE-2026-64709
CVE-2026-64735
CVE-2026-43739
CVE-2026-43816
CVE-2026-43822
CVE-2026-64729
CVE-2026-43814
CVE-2026-64700
CVE-2026-43799
CVE-2026-28931
CVE-2026-43817
CVE-2026-43769
CVE-2026-43810
CVE-2026-64775
CVE-2026-64720
CVE-2026-64751
CVE-2026-64721
CVE-2026-4424
CVE-2026-28973
CVE-2026-64739
CVE-2026-64743
CVE-2026-64724
CVE-2026-43723
CVE-2026-43733
CVE-2026-43729
CVE-2026-64772
CVE-2026-64771
CVE-2026-64722
CVE-2026-64774
CVE-2026-64770
CVE-2026-64769
CVE-2026-64768
CVE-2026-64711
CVE-2026-43812
CVE-2026-64741
CVE-2026-64766
CVE-2026-64765
CVE-2026-64764
CVE-2026-64763
CVE-2026-43800
CVE-2026-43740
CVE-2026-64713
CVE-2026-64730
CVE-2026-64728
CVE-2026-64783
CVE-2026-64757
CVE-2026-43804
CVE-2026-43821
CVE-2026-64718
CVE-2026-64719
CVE-2026-64726
CVE-2026-64755

+ About the security content of macOS Tahoe 26.6
https://support.apple.com/en-us/128067

+ About the security content of macOS Sequoia 15.7.8
https://support.apple.com/en-us/128071

+ About the security content of macOS Sonoma 14.8.8
https://support.apple.com/en-us/128072

+ About the security content of tvOS 26.6
https://support.apple.com/en-us/128069

+ About the security content of watchOS 26.6
https://support.apple.com/en-us/128068

+ About the security content of visionOS 26.6
https://support.apple.com/en-us/128070

+ About the security content of Safari 26.6
https://support.apple.com/en-us/128073

NEWS close-up
注目高まる「SCS評価制度」
Interopでも売り文句が飛び交った PマークやISMSと何が違うのか
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/071700334/?ST=nxt_thmit_security

変貌するCDN 第2回
CDNで「近い」サーバーに通信を導く仕組み、DNSとBGPを活用
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
日本交通、流出疑いの情報をネット上で確認 マルウエア感染で電話配車停止
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900374/?ST=nxt_thmit_security

2026年7月27日月曜日

27日 月曜日、先勝

+ ■Unboundの脆弱性情報が公開されました(CVE-2026-14586、他23件)
https://jprs.jp/tech/security/2026-07-24-unbound.html

+ RHSA-2026:46396 Important: libreswan security update
https://access.redhat.com/errata/RHSA-2026:46396
CVE-2026-12413
CVE-2026-14957
CVE-2026-50721
CVE-2026-50722

+ RHSA-2026:46391 Important: grafana security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:46391
CVE-2026-44740

+ RHSA-2026:45115 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:45115
CVE-2025-40026
CVE-2026-52993
CVE-2026-53059

+ RHSA-2026:46397 Important: libreswan security update
https://access.redhat.com/errata/RHSA-2026:46397
CVE-2026-12413
CVE-2026-14957
CVE-2026-50721
CVE-2026-50722

+ RHSA-2026:45192 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:45192
CVE-2025-40026
CVE-2026-52950
CVE-2026-52976
CVE-2026-53006
CVE-2026-53059

+ Mozilla Thunderbird 153.0.1 released
https://www.thunderbird.net/en-US/thunderbird/153.0.1esr/releasenotes/

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ Linux Kernelの脆弱性(RefluXFS:CVE-2026-64600)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260724/
CVE-2026-64600

JVNVU#93636354 CISA ICS Advisory / ICS Medical Advisory(2026年07月23日)
https://jvn.jp/vu/JVNVU93636354/index.html

JVNVU#99418634 Silverhand製Logtoにおける認証や認可に影響する複数の脆弱性
https://jvn.jp/vu/JVNVU99418634/index.html

piyokangoの月刊システムトラブル
UPSIDERに不正アクセス サプライチェーン攻撃に遭う
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/071600089/?ST=nxt_thmit_security

変貌するCDN 第1回
今やコンテンツ配信だけではないCDN、Web発展とともに多機能化
https://xtech.nikkei.com/atcl/nxt/column/18/03697/072200001/?ST=nxt_thmit_security

吉川孝志のマルウエア徹底解剖 第30回
生成AI時代に重要性が高まるサンドボックス、仕組みから包括的に解説する
https://xtech.nikkei.com/atcl/nxt/column/18/02805/071700031/?ST=nxt_thmit_security

北郷達郎のテクノロジー温故知新
「電話と紙」で育った技術記者が顧みる、情報収集方法の変遷
https://xtech.nikkei.com/atcl/nxt/column/18/02598/071700035/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第4回
セキュリティー要件の抜け漏れを防ぐ鉄則、まず検討項目を洗い出す
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800004/?ST=nxt_thmit_security

2026年7月24日金曜日

24日 金曜日、仏滅

+ Google Chrome 150.0.7871.186/.187 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01320465736.html

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

VU#492466 Logto Identity Platform has authentication and authorization failures in core protocol handling
https://www.kb.cert.org/vuls/id/492466

LLMを適所で生かす、セキュリティーの要件定義 第3回
要件決めの前に「保護ニーズ」を知ろう、対策のジャンルはLLMで把握
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800003/?ST=nxt_thmit_security

2026年7月23日木曜日

23日 木曜日、先負

+ ■(緊急)BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-13321)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec.html

+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-13204)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsecandnsec3.html

+ ■(緊急)BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-12617)
  - バージョンアップを強く推奨 -

https://jprs.jp/tech/security/2026-07-23-bind9-vuln-dnameandcname.html

+ ■(緊急)BIND 9.xの脆弱性(DNSキャッシュポイズニングの危険性)について(CVE-2026-11721)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-wildcard.html

+ ■(緊急)BIND 9.xの脆弱性(メモリ不足の発生)について(CVE-2026-11622)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-randomsubdomain.html

+ ■(緊急)BIND 9.xの脆弱性(過剰なCPU負荷の誘発)について(CVE-2026-11605)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-validation.html

+ ■(緊急)BIND 9.xの脆弱性(RPZの設定のバイパス、DNSサービスの停止)について(CVE-2026-11331)
 - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-rpz.html

+ ■BIND 9.xの脆弱性(DNSサービスの停止)について(CVE-2026-10822)
  - フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、
    バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-privatedns.html

+ ■BIND 9.xの脆弱性(名前解決の妨害)について(CVE-2026-10723)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2026-07-23-bind9-vuln-nsec3.html

+ Google Chrome 151.0.7922.47/.48, 150.0.7871.181/.182 released
https://chromereleases.googleblog.com/2026/07/early-stable-update-for-desktop_01571975877.html
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html

+ Mozillf Firefox 153.0 released
https://www.firefox.com/en-US/firefox/153.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-68 Security Vulnerabilities fixed in Firefox 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
CVE-2026-16349
CVE-2026-16350
CVE-2026-16362
CVE-2026-16351
CVE-2026-16352
CVE-2026-16363
CVE-2026-16364
CVE-2026-16365
CVE-2026-16366
CVE-2026-16353
CVE-2026-16354
CVE-2026-16367
CVE-2026-16368
CVE-2026-16369
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16370
CVE-2026-16371
CVE-2026-16372
CVE-2026-16373
CVE-2026-16374
CVE-2026-16375
CVE-2026-16376
CVE-2026-16377
CVE-2026-16378
CVE-2026-16379
CVE-2026-16358
CVE-2026-16380
CVE-2026-16381
CVE-2026-16382
CVE-2026-16383
CVE-2026-16384
CVE-2026-16385
CVE-2026-16386
CVE-2026-16387
CVE-2026-16388
CVE-2026-16389
CVE-2026-16390
CVE-2026-16391
CVE-2026-16392
CVE-2026-16393
CVE-2026-16359
CVE-2026-16394
CVE-2026-16395
CVE-2026-16396
CVE-2026-16397
CVE-2026-16398
CVE-2026-16399
CVE-2026-16400
CVE-2026-16401
CVE-2026-16402
CVE-2026-16403
CVE-2026-16404
CVE-2026-16405
CVE-2026-16406
CVE-2026-16407
CVE-2026-16408
CVE-2026-16409
CVE-2026-16410
CVE-2026-16411
CVE-2026-16412
CVE-2026-16360

+ Mozilla Foundation Security Advisory 2026-70 Security Vulnerabilities fixed in Firefox ESR 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/

+ Mozilla Foundation Security Advisory 2026-69 Security Vulnerabilities fixed in Firefox ESR 115.38
https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/

+ Mozilla Foundation Security Advisory 2026-71 Security Vulnerabilities fixed in Thunderbird 153
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/

+ Mozilla Foundation Security Advisory 2026-72 Security Vulnerabilities fixed in Thunderbird 140.13
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/

+ Mozilla Thunderbird 153.0 released
https://www.thunderbird.net/en-US/thunderbird/153.0esr/releasenotes/

+ ISC BIND 9.20.26 released
https://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html

+ Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html
CVE-2026-10723
CVE-2026-10822
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321

+ Linux Kernelの脆弱性(IPV6_FRAG_ESCAPE: CVE-2026-53362, CVE-2026-53366)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260723/
CVE-2026-53362
CVE-2026-53366

+ BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822)と修正バージョン(9.20.26, 9.21.24)
https://security.sios.jp/vulnerability/bind9-security-vulnerability-20260723/
CVE-2026-11331
CVE-2026-11605
CVE-2026-11622
CVE-2026-11721
CVE-2026-12617
CVE-2026-13204
CVE-2026-13321
CVE-2026-10723
CVE-2026-10822

+ Microsoft Edge <= 150.0.4078.48 (Chromium-based) Type Confusion RCE
https://cxsecurity.com/issue/WLB-2026070009
CVE-2026-58289

VU#847406 Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability
https://www.kb.cert.org/vuls/id/847406

VU#360868 Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability
https://www.kb.cert.org/vuls/id/360868

VU#762226 Plane contains multi-tenant authorization bypass vulnerability
https://www.kb.cert.org/vuls/id/762226

JVNVU#98636554 バックアップソフトウェア「Duplicati」における不適切な権限割り当てに関する脆弱性
https://jvn.jp/vu/JVNVU98636554/index.html

JVNVU#98875819 Analog Way製メディアサーバー「Picturall Quad Compact Mark II」におけるローカル権限昇格の脆弱性
https://jvn.jp/vu/JVNVU98875819/index.html

JVN#32082029 リコー製プリンターおよび複合機のSSH通信機能におけるアクセス制御不備の脆弱性
https://jvn.jp/jp/JVN32082029/index.html

JVNVU#90683587 プロジェクト管理ツール「Plane」における認可回避の脆弱性
https://jvn.jp/vu/JVNVU90683587/index.html

JVNVU#98832565 CISA ICS Advisory / ICS Medical Advisory(2026年07月21日)
https://jvn.jp/vu/JVNVU98832565/index.html

JVN#20592637 Drupalプラグイン「AI Agents」における不正な認証の脆弱性
https://jvn.jp/jp/JVN20592637/index.html

JVN#40509781 非接触型ICカード技術FeliCaの一部のICチップにおける脆弱性
https://jvn.jp/jp/JVN40509781/index.html

ニュース&リポート
26年度末開始「SCS評価制度」に脚光 供給網のサイバー対策を客観評価
展示会Interopで関連サービスが多数出展
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/071301466/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第2回
セキュリティー要件は6ステップで定義 LLMを生かしてまずは脅威を理解
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800002/?ST=nxt_thmit_security

ニュース解説
OpenAIのモデルが他社システムに侵入、ゼロデイ悪用でサンドボックス脱出
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11912/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIエージェントによる「ランサムウエア攻撃」出現、侵入から脅迫まで全自動
https://xtech.nikkei.com/atcl/nxt/column/18/00676/071100229/?ST=nxt_thmit_security

LLMを適所で生かす、セキュリティーの要件定義 第1回
「残念なセキュリティー」を招く要件定義の落とし穴、3大パターンを紹介
https://xtech.nikkei.com/atcl/nxt/column/18/03679/070800001/?ST=nxt_thmit_security

日経コンピュータ「動かないコンピュータ」
顧客情報1354万件漏洩の恐れ SSD紛失、例外運用のリスク露呈
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/071300211/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
シード・プランニング、PHP脆弱性でランサムウエア被害 影響範囲を廃棄
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900373/?ST=nxt_thmit_security

2026年7月17日金曜日

17日 金曜日、先負

+ RHSA-2026:40894 Important: hplip security update
https://access.redhat.com/errata/RHSA-2026:40894
CVE-2026-14544

+ RHSA-2026:40841 Important: maven:3.8 security update
https://access.redhat.com/errata/RHSA-2026:40841
CVE-2025-67030

+ RHSA-2026:40895 Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
https://access.redhat.com/errata/RHSA-2026:40895
CVE-2026-54512
CVE-2026-54513

+ RHSA-2026:40831 Important: hplip security update
https://access.redhat.com/errata/RHSA-2026:40831
CVE-2026-14544

+ RHSA-2026:40751 Important: gimp security update
https://access.redhat.com/errata/RHSA-2026:40751
CVE-2026-58380
CVE-2026-58384

+ Google Chrome 150.0.7871.128/.129 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_049796704.html

+ Oracle Critical Patch Update Pre-Release Announcement - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ JVN#65294474 Tera TermのTTSSH2プラグインにおける複数の脆弱性
https://jvn.jp/jp/JVN65294474/index.html
CVE-2026-58317
CVE-2026-60060

+ JVNVU#95286373 Apache Tomcatにおける複数の脆弱性(2026年7月14日)
https://jvn.jp/vu/JVNVU95286373/index.html
CVE-2026-59083
CVE-2026-59084

VU#885548 Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions
https://www.kb.cert.org/vuls/id/885548

VU#326070 SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem
https://www.kb.cert.org/vuls/id/326070

JVNVU#90340653 Pegatron製Windows Driver Model (WDM) ドライバー「Tdelo64.sys」における複数の脆弱性
https://jvn.jp/vu/JVNVU90340653/index.html

JVNVU#98998987 JavaScriptライブラリ「Forge」における複数の署名検証不備の脆弱性
https://jvn.jp/vu/JVNVU98998987/index.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
「AI駆動型ワーム」の脅威 自律的に脆弱性を見つけて感染
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/070700190/?ST=nxt_thmit_security

基礎から分かる、AIエージェントのセキュリティー設計 第3回
何をどう判断しどう行動したのか、AIエージェントを「追跡」するログ設計
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000003/?ST=nxt_thmit_security

2026年7月16日木曜日

16日 木曜日、友引

+ RHSA-2026:39893 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:39893
CVE-2026-15308

+ RHSA-2026:39868 Important: nodejs:24 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39868
CVE-2026-6733
CVE-2026-6734
CVE-2026-9678
CVE-2026-9697
CVE-2026-11525
CVE-2026-12151
CVE-2026-42338
CVE-2026-48615
CVE-2026-48618
CVE-2026-48619
CVE-2026-48928
CVE-2026-48930
CVE-2026-48933
CVE-2026-48934
CVE-2026-48935

+ RHSA-2026:39575 Important: cifs-utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39575
CVE-2026-12505

+ RHSA-2026:40416 Low: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:40416
CVE-2026-14355

+ RHSA-2026:39879 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:39879
CVE-2026-27145
CVE-2026-39821

+ RHSA-2026:39810 Important: Red Hat OpenStack Services on OpenShift 18.0 (golang-github-openstack-k8s-operators-os-diff) security update
https://access.redhat.com/errata/RHSA-2026:39810
CVE-2025-61726
CVE-2025-61729
CVE-2026-25679
CVE-2026-27137
CVE-2026-32280
CVE-2026-32281
CVE-2026-32282
CVE-2026-32283
CVE-2026-33810
CVE-2026-33811

+ RHSA-2026:39798 Important: python3.9 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39798
CVE-2026-15308

+ RHSA-2026:39771 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:39771
CVE-2026-15308

+ RHSA-2026:39576 Important: cifs-utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:39576
CVE-2026-12505

+ Google Chrome 151.0.7922.34/.35 released
https://chromereleases.googleblog.com/2026/07/early-stable-update-for-desktop.html

+ Mozilla Firefox 152.0.6 released
https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/

+ nginx 1.31.3. 1.30.4 released
https://nginx.org/en/CHANGES
https://nginx.org/en/CHANGES-1.30

+ K000162097: NGINX map directive and regex matching vulnerability CVE-2026-42533
https://my.f5.com/manage/s/article/K000162097
CVE-2026-42533

+ K000162100: NGINX ngx_http_slice_module vulnerability CVE-2026-60005
https://my.f5.com/manage/s/article/K000162100
CVE-2026-60005

+ K000162098: NGINX ngx_http_ssi_module vulnerability CVE-2026-56434
https://my.f5.com/manage/s/article/K000162098
CVE-2026-56434

+ Apache PDFBox 2.0.37 released
https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310760&version=12356771

VU#529388 Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys
https://www.kb.cert.org/vuls/id/529388

VU#725167 node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations
https://www.kb.cert.org/vuls/id/725167

基礎から分かる、AIエージェントのセキュリティー設計 第2回
AIエージェントのID管理に4つの課題、過剰な権限を持たせず「小さく」設計
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000002/?ST=nxt_thmit_security

ニュース解説
ニチレイ不正アクセス「東西両センターで障害」、井村屋は15日分納品を中止
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11899/?ST=nxt_thmit_security

JVN#59875262 HYPER SBI 2のインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN59875262/index.html

JVNVU#91295052 Siemens製品に対するアップデート(2026年7月)
https://jvn.jp/vu/JVNVU91295052/index.html

JVNVU#91675472 CISA ICS Advisory / ICS Medical Advisory(2026年07月14日)
https://jvn.jp/vu/JVNVU91675472/index.html

2026年7月15日水曜日

15日 水曜日、先勝

+ RHSA-2026:39320 Important: python3 security update
https://access.redhat.com/errata/RHSA-2026:39320
CVE-2026-15308

+ RHSA-2026:39266 Important: git-lfs security update
https://access.redhat.com/errata/RHSA-2026:39266
CVE-2026-33811

+ RHSA-2026:39127 Important: python-pillow security update
https://access.redhat.com/errata/RHSA-2026:39127
CVE-2026-54059
CVE-2026-54060
CVE-2026-55379
CVE-2026-55380

+ RHSA-2026:39083 Important: kernel update
https://access.redhat.com/errata/RHSA-2026:39083
CVE-2025-71066
CVE-2025-71089
CVE-2026-31411
CVE-2026-43499
CVE-2026-46113
CVE-2026-53166
CVE-2026-53266
CVE-2026-53359

+ RHSA-2026:38995 Important: go-toolset:rhel8 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:38995
CVE-2026-27145
CVE-2026-39821
CVE-2026-39822

+ RHSA-2026:38901 Important: perl-DBI:1.641 security update
https://access.redhat.com/errata/RHSA-2026:38901
CVE-2026-9698

+ RHSA-2026:38847 Important: nginx:1.24 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:38847
CVE-2026-42055

+ RHSA-2026:38488 Important: xorg-x11-server-Xwayland security update
https://access.redhat.com/errata/RHSA-2026:38488
CVE-2026-55999

+ RHSA-2026:38485 Important: gegl security update
https://access.redhat.com/errata/RHSA-2026:38485
CVE-2026-2050

+ RHSA-2026:39553 Important: perl-XML-LibXML security update
https://access.redhat.com/errata/RHSA-2026:39553
CVE-2026-8177

+ RHSA-2026:39319 Important: git-lfs security update
https://access.redhat.com/errata/RHSA-2026:39319
CVE-2026-33811

+ RHSA-2026:39309 Low: capstone security update
https://access.redhat.com/errata/RHSA-2026:39309
CVE-2025-68114

+ RHSA-2026:38493 Important: buildah security update
https://access.redhat.com/errata/RHSA-2026:38493
CVE-2026-39822

+ RHSA-2026:38490 Important: xorg-x11-server-Xwayland security update
https://access.redhat.com/errata/RHSA-2026:38490
CVE-2026-55999
CVE-2026-56000

+ Google Chrome 150.0.7871.124/.125 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0353146366.html

+ Mozilla Foundation Security Advisory 2026-67 Security Vulnerabilities fixed in Firefox 152.0.6
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/
CVE-2026-15718
CVE-2026-15719

+ 2026 年 7 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/07/202607-security-update

基礎から分かる、AIエージェントのセキュリティー設計 第1回
AIエージェントは何が「危ない」のか、自律レベルとリスクの関係を理解する
https://xtech.nikkei.com/atcl/nxt/column/18/03687/071000001/?ST=nxt_thmit_security

2026年7月14日火曜日

14日 火曜日、赤口

+ JVNVU#94203999 GNU Wgetにおけるサーバサイドリクエストフォージェリの脆弱性
https://jvn.jp/vu/JVNVU94203999/index.html
CVE-2026-15146

JVNVU#94039788 iOS版LINEにおけるサービス運用妨害(DoS)につながる脆弱性
https://jvn.jp/vu/JVNVU94039788/index.html

piyokangoの週刊システムトラブル
オーミケンシ、有価証券報告書の提出延期 VPN経由侵入で基幹システム停止
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900372/?ST=nxt_thmit_security

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第4回
アサヒなど被害企業20社超の再発防止策を分析、レジリエンス重視が鮮明に
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800004/?ST=nxt_thmit_security

2026年7月13日月曜日

13日 月曜日、先負

+ Apache PDFBox 3.0.8 released
https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310760&version=12356674

VU#564823 GNU Wget enables SSRF via unvalidated FTP PASV IPs
https://www.kb.cert.org/vuls/id/564823

JVNVU#91295052 Siemens製品に対するアップデート(2026年7月)
https://jvn.jp/vu/JVNVU91295052/index.html

JVNVU#94281476 CISA ICS Advisory / ICS Medical Advisory(2026年07月09日)
https://jvn.jp/vu/JVNVU94281476/index.html

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第3回
サイバー攻撃の損失を新たに28社が計上、アサヒらの影響で総額は236億円に
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800003/?ST=nxt_thmit_security

2026年7月10日金曜日

10日 金曜日、赤口

+ gawk 5.4.1 released
https://ftp.gnu.org/gnu/gawk/?C=M;O=D

+ RHSA-2026:37282 Important: unbound security update
https://access.redhat.com/errata/RHSA-2026:37282
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-44390

+ RHSA-2026:37130 Important: gstreamer1-plugins-bad-free security update
https://access.redhat.com/errata/RHSA-2026:37130
CVE-2026-52720
CVE-2026-52722

+ RHSA-2026:37435 Important: golang security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:37435
CVE-2026-39821
CVE-2026-39822

+ RHSA-2026:37410 Important: buildah security update
https://access.redhat.com/errata/RHSA-2026:37410
CVE-2026-39832
CVE-2026-39835

+ RHSA-2026:37207 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:37207
CVE-2026-45700

+ RHSA-2026:37123 Important: podman security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:37123
CVE-2026-25681
CVE-2026-27136
CVE-2026-39829
CVE-2026-39832
CVE-2026-39835
CVE-2026-42508
CVE-2026-57231

+ RHSA-2026:36957 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:36957
CVE-2025-71066
CVE-2026-46113
CVE-2026-53359

+ Wireshark 4.6.7, 4.4.17 released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.7.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.17.html

VU#152953 PayRange Android app version 7.0.7 contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/152953

VU#734812 Xerte Online Toolkit contains an authentication bypass that allows for RCE
https://www.kb.cert.org/vuls/id/734812

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第2回
サイバー詐欺で18社が損失を計上 海外拠点で頻発、支払い統制がカギか
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800002/?ST=nxt_thmit_security

JVNVU#99220646 Adalo App Builderにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99220646/index.html

JVN#48718197 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)における反射型クロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN48718197/index.html

2026年7月9日木曜日

9日 木曜日、大安

+ RHSA-2026:36774 Important: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:36774
CVE-2026-53705

+ RHSA-2026:36732 Moderate: python-urllib3 security update
https://access.redhat.com/errata/RHSA-2026:36732
CVE-2026-44431

+ RHSA-2026:36734 Low: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:36734
CVE-2025-6170

+ RHSA-2026:36733 Moderate: cups security update
https://access.redhat.com/errata/RHSA-2026:36733
CVE-2026-34980

+ RHSA-2026:36728 Low: libtasn1 security update
https://access.redhat.com/errata/RHSA-2026:36728
CVE-2025-13151

+ RHSA-2026:36530 Important: kpatch-patch-4_18_0-553_109_1, kpatch-patch-4_18_0-553_125_1, kpatch-patch-4_18_0-553_53_1, kpatch-patch-4_18_0-553_72_1, and kpatch-patch-4_18_0-553_85_1 security update
https://access.redhat.com/errata/RHSA-2026:36530
CVE-2026-23401
CVE-2026-31402
CVE-2026-31419

+ RHSA-2026:36879 Important: tomcat security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:36879
CVE-2026-29146
CVE-2026-34486

+ RHSA-2026:36832 Important: libreoffice security update
https://access.redhat.com/errata/RHSA-2026:36832
CVE-2026-8357

+ RHSA-2026:36777 Important: unbound security update
https://access.redhat.com/errata/RHSA-2026:36777
CVE-2026-40622
CVE-2026-41292
CVE-2026-42534
CVE-2026-44390

+ RHSA-2026:36674 Moderate: gstreamer1-plugins-ugly-free security update
https://access.redhat.com/errata/RHSA-2026:36674
CVE-2026-53703
CVE-2026-53704

+ RHSA-2026:36617 Important: oci-seccomp-bpf-hook security update
https://access.redhat.com/errata/RHSA-2026:36617
CVE-2026-33811

+ Google Chrome 150.0.7871.114/.115 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html

+ Apache Tomcat 11.0.24, 10.1.57 Released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.24_(markt)
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.57_(schultz)

+ ProFTPD 1.3.9c released
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.9c
http://www.proftpd.org/docs/NEWS-1.3.9c

+ OpenSSHの脆弱性(Moderate: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999)とOpenSSH 10.4/10.4p1リリース
https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260709/
CVE-2026-59995
CVE-2026-59996
CVE-2026-59997
CVE-2026-59998
CVE-2026-59999

VU#849433 Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls
https://www.kb.cert.org/vuls/id/849433

JVN#62347140 富士電機製Pupsmanのインストーラにおける複数の脆弱性
https://jvn.jp/jp/JVN62347140/index.html

JVNVU#92734392 CISA ICS Advisory / ICS Medical Advisory(2026年07月07日)
https://jvn.jp/vu/JVNVU92734392/index.html

決算調査で判明、企業を襲うサイバー詐欺とサイバー攻撃 第1回
出光は36億円を損失か、ランサム並みに深刻な「サイバー詐欺」の実態
https://xtech.nikkei.com/atcl/nxt/column/18/03678/070800001/?ST=nxt_thmit_security

3分でわかる必修ワード IT
万全の対策は難しい「シャドーAI」、企業はガバナンスやルール整備を進める
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/070600320/?ST=nxt_thmit_security

2026年7月8日水曜日

8日 水曜日、仏滅

+ RHSA-2026:36366 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:36366
CVE-2026-43112

+ RHSA-2026:36349 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:36349
CVE-2025-10263
CVE-2026-43198
CVE-2026-43450
CVE-2026-46209
CVE-2026-46227
CVE-2026-46259

+ RHSA-2026:36307 Moderate: freeipmi security update
https://access.redhat.com/errata/RHSA-2026:36307
CVE-2026-50031

+ RHSA-2026:36215 Important: compat-openssl10 security update
https://access.redhat.com/errata/RHSA-2026:36215
CVE-2026-45447

+ RHSA-2026:36201 Important: 389-ds:1.4 security update
https://access.redhat.com/errata/RHSA-2026:36201
CVE-2026-11610
CVE-2026-11774

+ RHSA-2026:36315 Important: python3.14-pip security update
https://access.redhat.com/errata/RHSA-2026:36315
CVE-2026-8643

+ RHSA-2026:36210 Moderate: freeipmi security update
https://access.redhat.com/errata/RHSA-2026:36210
CVE-2026-50031

+ RHSA-2026:36195 Important: 389-ds-base security update
https://access.redhat.com/errata/RHSA-2026:36195
CVE-2026-11610
CVE-2026-11774

+ RHSA-2026:36172 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:36172
CVE-2026-31419

+ Google Chrome 150.0.7871.100/.101 released
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop.html

+ Mozilla Firefox 152.0.5 released
https://www.firefox.com/en-US/firefox/152.0.5/releasenotes/

+ Zabbix 7.0.28, 6.0.47 released
https://www.zabbix.com/rn/rn7.0.28
https://www.zabbix.com/rn/rn6.0.47

+ Apache Tomcat 9.0.120 Released
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.120_(remm)

+ Linux Kernelの脆弱性(Januscape: CVE-2026-53359)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260707/
CVE-2026-53359

UPDATE: JVN#90566559 Apache Jena Fusekiにおけるパストラバーサルの脆弱性
https://jvn.jp/jp/JVN90566559/index.html

JVN#87285119 複数のセイコーエプソン製プリンターおよびスキャナーのWeb Configにおけるクロスサイトリクエストフォージェリの脆弱性
https://jvn.jp/jp/JVN87285119/index.html

JVNVU#93316066 Tenda製品の複数のファームウェアにおけるセキュリティ上問題のある隠し機能の脆弱性
https://jvn.jp/vu/JVNVU93316066/index.html

JVNVU#90409906 HP Deskjet 2800プリンターシリーズにおける認証不備の脆弱性
https://jvn.jp/vu/JVNVU90409906/index.html

日経コンピュータ「ITが危ない」
シャドーAIのリスクが顕在化 国内企業の7割超が対策できず
放置で情報漏洩・法令違反のリスクも
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/070100198/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
「AI駆動型ワーム」の脅威 自律的に脆弱性を見つけて感染、特定率は8割超
https://xtech.nikkei.com/atcl/nxt/column/18/00676/070100228/?ST=nxt_thmit_security

KDDIメール基盤から1223万人分のアドレス漏洩、ソフト会社も脆弱性認識せず
https://xtech.nikkei.com/atcl/nxt/news/24/03297/?ST=nxt_thmit_security

2026年7月7日火曜日

7日 火曜日、先負

+ OpenSSH 10.4 released
https://www.openssh.org/releasenotes.html#10.4

+ Postfix stable release 3.11.5 and legacy releases 3.10.12, 3.9.13, 3.8.19, 3.7.21, 3.6.19, 3.5.26
https://www.postfix.org/announcements/postfix-3.11.5.html

+ PostgreSQL JDBC Driver 42.7.13 released
https://jdbc.postgresql.org/changelogs/2026-07-06-42.7.13-release/

VU#213560 Tenda firmware (multiple versions) contains hidden authentication backdoor
https://www.kb.cert.org/vuls/id/213560

VU#828543 HP Deskjet 2800 Printer Series Webservers contain Missing Authorization Vulnerability
https://www.kb.cert.org/vuls/id/828543

piyokangoの週刊システムトラブル
BitStar、引き継いだBoka nii事業のXアカウントを奪われる 管理不備で
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900371/?ST=nxt_thmit_security

2026年7月6日月曜日

6日 月曜日、友引

+ RHSA-2026:35831 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:35831
CVE-2026-39821

+ RHSA-2026:35830 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:35830
CVE-2026-39821

+ RHSA-2026:35828 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:35828
CVE-2026-39821

+ 7-Zip <= 26.02 - Mark-of-the-Web (MotW) Bypass via RAR5 Alternate Data Stream Name Collision
https://cxsecurity.com/issue/WLB-2026070002
CVE-2026-58052

JVNVU#98406800 Little Orbit製GamersFirst Anti-Cheatにおける複数のローカル特権昇格の脆弱性
https://jvn.jp/vu/JVNVU98406800/index.html

JVNVU#97594085 CISA ICS Advisory / ICS Medical Advisory(2026年07月02日)
https://jvn.jp/vu/JVNVU97594085/index.html

日経コンピュータ「動かないコンピュータ」
コード管理基盤から個人情報漏洩か 銀行口座との連携機能が一斉停止に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/070200210/?ST=nxt_thmit_security

フォーカス
「Mythos」の衝撃 脆弱性の嵐に備えよ
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600014/070200231/?ST=nxt_thmit_security

2026年7月3日金曜日

3日 金曜日、大安

+ PHP 8.5.8, 8.4.23, 8.3.32, 8.2.32 released
https://www.php.net/ChangeLog-8.php#8.5.8
https://www.php.net/ChangeLog-8.php#8.4.23
https://www.php.net/ChangeLog-8.php#8.3.32
https://www.php.net/ChangeLog-8.php#8.2.32

VU#639124 Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat
https://www.kb.cert.org/vuls/id/639124

UPDATE: JVNVU#92054409 三菱電機製数値制御装置における数値の入力に対する不適切な検証
https://jvn.jp/vu/JVNVU92054409/index.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIで巧妙化するフィッシング 件数は20%減でも被害額は3倍
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/063000189/?ST=nxt_thmit_security

マルウエア徹底解剖
IoT機器を狙うマルウエア [第79回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/061700080/?ST=nxt_thmit_security

2026年7月2日木曜日

2日 木曜日、仏滅

+ MantisBT 2.28.4 released
https://mantisbt.org/blog/archives/mantisbt/852

+ RHSA-2026:34367 Important: Satellite 6.16.10 Async Update
https://access.redhat.com/errata/RHSA-2026:34367
CVE-2026-5135
CVE-2026-5136
CVE-2026-5138
CVE-2026-5142

+ RHSA-2026:34354 Important: php:7.4 security update
https://access.redhat.com/errata/RHSA-2026:34354
CVE-2026-6722
CVE-2026-6735
CVE-2026-7258
CVE-2026-7261
CVE-2026-7262
CVE-2026-7568

+ RHSA-2026:34155 Moderate: rrdtool security update
https://access.redhat.com/errata/RHSA-2026:34155
CVE-2026-43958

+ RHSA-2026:34368 Important: Satellite 6.18.7 Async Update
https://access.redhat.com/errata/RHSA-2026:34368
CVE-2026-5135
CVE-2026-5136
CVE-2026-5138
CVE-2026-5142
CVE-2026-32282
CVE-2026-40192

+ RHSA-2026:34366 Important: Satellite 6.17.9 Async Update
https://access.redhat.com/errata/RHSA-2026:34366
CVE-2026-5135
CVE-2026-5136
CVE-2026-5138
CVE-2026-5142
CVE-2026-32282
CVE-2026-40192

+ RHSA-2026:34365 Important: Satellite 6.19.2 Async Update
https://access.redhat.com/errata/RHSA-2026:34365
CVE-2026-5135
CVE-2026-5136
CVE-2026-5138
CVE-2026-5142
CVE-2026-25679
CVE-2026-27727
CVE-2026-32280
CVE-2026-32281
CVE-2026-32282
CVE-2026-32283
CVE-2026-33810
CVE-2026-40192
CVE-2026-48526

+ RHSA-2026:34359 Important: opentelemetry-collector security update
https://access.redhat.com/errata/RHSA-2026:34359
CVE-2026-25681
CVE-2026-27145
CVE-2026-33811
CVE-2026-39821
CVE-2026-42151
CVE-2026-42154

+ RHSA-2026:34156 Moderate: rrdtool security update
https://access.redhat.com/errata/RHSA-2026:34156
CVE-2026-43958

+ Mozilla Foundation Security Advisory 2026-63 Security Vulnerabilities fixed in Thunderbird 152.0.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-63/
CVE-2026-57962
CVE-2026-57963

+ Mozilla Foundation Security Advisory 2026-64 Security Vulnerabilities fixed in Thunderbird 140.12.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/
CVE-2026-57962
CVE-2026-57963

+ Mozilla Thnderbird 152.0.1, 140.12.1 released
https://www.thunderbird.net/en-US/thunderbird/152.0.1/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/140.12.1/releasenotes/

+ ClamAV 1.5.3 and 1.4.5 security patch versions published
https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html
CVE-2026-20217
CVE-2026-20213
CVE-2026-20216
CVE-2026-20214
CVE-2026-20243
CVE-2026-20215
CVE-2026-20244

+ JVNVU#93304382 Apache Tomcatにおける複数の脆弱性(2026年6月29日)
https://jvn.jp/vu/JVNVU93304382/index.html
CVE-2026-55957
CVE-2026-55956
CVE-2026-55955
CVE-2026-55276
CVE-2026-53434
CVE-2026-53404
CVE-2026-50229

JVN#20721579 セイコーソリューションズ製SkyBridge MB-A100/MB-A110におけるOSコマンドインジェクションの脆弱性
https://jvn.jp/jp/JVN20721579/index.html

JVNVU#99876312 CISA ICS Advisory / ICS Medical Advisory(2026年06月30日)
https://jvn.jp/vu/JVNVU99876312/index.html

JVNVU#93818675 Siemens製品に対するアップデート(2026年6月)
https://jvn.jp/vu/JVNVU93818675/index.html

絵で見て分かるネットワーク必修キーワード
SNMP
機器の情報を集めてネットワークの状態を監視
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091900172/061600034/?ST=nxt_thmit_security

記者の眼
「メールが届かなくても仕方ない」を普通にしませんか
https://xtech.nikkei.com/atcl/nxt/column/18/00138/063002060/?ST=nxt_thmit_security

AnthropicがFable 5の提供再開へ、およそ2週間ぶり 米商務省が輸出規制解除
https://xtech.nikkei.com/atcl/nxt/news/24/03282/?ST=nxt_thmit_security