2026年8月14日金曜日

14日 金曜日、友引

+ RHSA-2026:54654 Important: bind security update
https://access.redhat.com/errata/RHSA-2026:54654
CVE-2026-10723
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54575 Important: dracut security update
https://access.redhat.com/errata/RHSA-2026:54575
CVE-2026-15816

+ RHSA-2026:54542 Important: .NET 10.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:54542
CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

+ RHSA-2026:54538 Important: .NET 8.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:54538
CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

+ RHSA-2026:54509 Important: bind9.16 security update
https://access.redhat.com/errata/RHSA-2026:54509
CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54485 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:54485
CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

+ RHSA-2026:54662 Moderate: nghttp2 security update
https://access.redhat.com/errata/RHSA-2026:54662
CVE-2026-58055

+ RHSA-2026:54571 Important: dracut security update
https://access.redhat.com/errata/RHSA-2026:54571
CVE-2026-15816

+ RHSA-2026:54510 Important: bind security update
https://access.redhat.com/errata/RHSA-2026:54510
CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54487 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:54487
CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

+ RHSA-2026:54484 Moderate: python-idna security update
https://access.redhat.com/errata/RHSA-2026:54484
CVE-2026-45409

+ Microsoft Drivers for PHP for SQL Server 5.13.2 released
https://learn.microsoft.com/ja-jp/sql/connect/php/download-drivers-php-sql-server?view=sql-server-ver17

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ Unbounded Memory Growth in QUIC Server Incoming Channel Queue
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-14456
CVE-2026-14456

+ PostgreSQL 18.6, 17.11, 16.15, 15.19, 14.24 and 19 Beta 3 Released!
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
https://www.postgresql.org/docs/18/release-18-6.html
https://www.postgresql.org/docs/17/release-17-11.html
https://www.postgresql.org/docs/16/release-16-15.html
https://www.postgresql.org/docs/15/release-15-19.html
https://www.postgresql.org/docs/14/release-14-24.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
ランサムウエア攻撃者の侵入経路 脆弱性悪用を抜きメールが首位に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/080500192/?ST=nxt_thmit_security

JVN#00941257 VoiceTraにおける接続先の制限が不適切な脆弱性
https://jvn.jp/jp/JVN00941257/index.html

2026年8月13日木曜日

13日 木曜日、先勝

+ ■PowerDNS Authoritative Serverの脆弱性情報が公開されました (CVE-2026-52682)
https://jprs.jp/tech/security/2026-08-12-powerdns-auth.html

+ ■PowerDNS Recursorの脆弱性情報が公開されました(CVE-2026-52682)
https://jprs.jp/tech/security/2026-08-12-powerdns-recursor.html

+ RHSA-2026:54371 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:54371
CVE-2026-11822
CVE-2026-11824
CVE-2026-14257
CVE-2026-54272
CVE-2026-69152
CVE-2026-69192

+ RHSA-2026:54290 Moderate: python-idna security update
https://access.redhat.com/errata/RHSA-2026:54290
CVE-2026-45409

+ RHSA-2026:54272 Important: abrt security update
https://access.redhat.com/errata/RHSA-2026:54272
CVE-2026-54228
CVE-2026-54229
CVE-2026-54230
CVE-2026-54231

+ RHSA-2026:54246 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2026:54246
CVE-2026-45991
CVE-2026-53009

+ RHSA-2026:54243 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:54243
CVE-2026-33377
CVE-2026-42127

+ RHSA-2026:54268 Important: python3.9 security update
https://access.redhat.com/errata/RHSA-2026:54268
CVE-2026-11940

+ RHSA-2026:54184 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:54184
CVE-2026-42127

+ Google Chrome 152.0.7977.42/.43 released
https://chromereleases.googleblog.com/2026/08/early-stable-update-for-desktop.html

+ Mozilla Firefox 153.0.4 released
https://www.firefox.com/en-US/firefox/153.0.4/releasenotes/

+ Wireshark 4.6.8, 4.4.18 released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.8.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.18.html

+ 2026 年 8 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/08/202608-security-update

+ OpenSSHの脆弱性(Medium: CVE-2026-73282, Low: CVE-2026-73281, CVE-2026-73283)とOpenSSH 10.5リリース
https://security.sios.jp/vulnerability/openssh-security-vulnerability-20260812/
CVE-2026-73282
CVE-2026-73281
CVE-2026-73283

現場から始めるデータ活用 当事者意識の持ち方・持たせ方
「Excelでこっそり共有」はやめよう 現場のセキュリティー意識が鍵に [第7回]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/022000534/080600007/?ST=nxt_thmit_security

ニュース解説
OpenAIが先端AIのガードレール緩和、一部個人・組織で 中国モデルに危機感
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11962/?ST=nxt_thmit_security

JVNVU#96623328 TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727)
https://jvn.jp/vu/JVNVU96623328/index.html

JVNVU#96740507 ECプラットフォーム「Opencart」におけるディレクトリトラバーサルの脆弱性
https://jvn.jp/vu/JVNVU96740507/index.html

JVNVU#98375707 Siemens製品に対するアップデート(2026年8月)
https://jvn.jp/vu/JVNVU98375707/index.html

JVNVU#95587179 CISA ICS Advisory / ICS Medical Advisory(2026年08月11日)
https://jvn.jp/vu/JVNVU95587179/index.html

2026年8月12日水曜日

12日 水曜日、大安

+ RHSA-2026:53848 Important: isns-utils security update
https://access.redhat.com/errata/RHSA-2026:53848
CVE-2026-55995

+ RHSA-2026:53363 Important: fence-agents security update
https://access.redhat.com/errata/RHSA-2026:53363
CVE-2026-59886

+ RHSA-2026:52949 Important: java-1.8.0-ibm security update
https://access.redhat.com/errata/RHSA-2026:52949
CVE-2026-8400
CVE-2026-16243
CVE-2026-16439
CVE-2026-16441
CVE-2026-41254
CVE-2026-46968
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-47057
CVE-2026-47058
CVE-2026-47059
CVE-2026-47063
CVE-2026-60147

+ RHSA-2026:52772 Important: perl-DBI:1.641 security update
https://access.redhat.com/errata/RHSA-2026:52772
CVE-2026-14380
CVE-2026-14739

+ RHSA-2026:52765 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2026:52765
CVE-2026-64496

+ RHSA-2026:52396 Important: postgresql:12 security update
https://access.redhat.com/errata/RHSA-2026:52396
CVE-2026-6479

+ RHSA-2026:53847 Important: isns-utils security update
https://access.redhat.com/errata/RHSA-2026:53847
CVE-2026-55995

+ RHSA-2026:53452 Moderate: gstreamer1-plugins-good security update
https://access.redhat.com/errata/RHSA-2026:53452
CVE-2026-18649

+ RHSA-2026:53329 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:53329
CVE-2025-54518
CVE-2026-31530
CVE-2026-64368
CVE-2026-64531

+ RHSA-2026:52674 Moderate: libarchive security update
https://access.redhat.com/errata/RHSA-2026:52674
CVE-2026-14164

+ Google Chrome 151.0.7922.137/.138, 150.0.7871.230 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_01815628406.html
https://chromereleases.googleblog.com/2026/08/extended-stable-update-for-desktop_01657873926.html

+ Mozilla Thunderbird 153.0.3 released
https://www.thunderbird.net/en-US/thunderbird/153.0.3/releasenotes/

+ OpenSSH 10.5 released
https://www.openssh.org/releasenotes.html#10.5

+ Postfix stable release 3.11.6 and legacy releases 3.10.13, 3.9.14, 3.8.20, 3.7.22, 3.6.20, 3.5.27
https://www.postfix.org/announcements/postfix-3.11.6.html

VU#431093 TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
https://www.kb.cert.org/vuls/id/431093

VU#614868 Opencart ecommerce platform contains directory traversal vulnerability
https://www.kb.cert.org/vuls/id/614868

ニュース解説
OpenAI、次世代AI「Astra」の開発を一部停止 高いサイバー攻撃能力を懸念
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11960/?ST=nxt_thmit_security

JVN#40467227 LINE PC版(Windows版)のインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN40467227/index.html

JVNVU#91804527 CISA ICS Advisory / ICS Medical Advisory(2026年08月07日)
https://jvn.jp/vu/JVNVU91804527/index.html

JVNVU#95261826 nothingsのstb TrueTypeライブラリにおけるヒープベースのバッファオーバーフローの脆弱性
https://jvn.jp/vu/JVNVU95261826/index.html