2026年5月20日水曜日

20日 水曜日、先勝

+ RHSA-2026:19372 Critical: nginx:1.26 security update
https://access.redhat.com/errata/RHSA-2026:19372
CVE-2026-42945

+ RHSA-2026:19373 Important: dnsmasq security update
https://access.redhat.com/errata/RHSA-2026:19373
CVE-2026-2291
CVE-2026-4890
CVE-2026-4891
CVE-2026-4892
CVE-2026-4893

+ RHSA-2026:19374 Critical: nginx security update
https://access.redhat.com/errata/RHSA-2026:19374
CVE-2026-42945

+ RHSA-2026:19369 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:19369
CVE-2026-32282
CVE-2026-32283

+ RHSA-2026:19371 Critical: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:19371
CVE-2026-42945

+ RHSA-2026:19370 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:19370
CVE-2026-7320
CVE-2026-7321
CVE-2026-7322
CVE-2026-7323

+ RHSA-2026:19368 Important: rsync security update
https://access.redhat.com/errata/RHSA-2026:19368
CVE-2024-12086
CVE-2026-41035

+ RHSA-2026:19367 Important: giflib update
https://access.redhat.com/errata/RHSA-2026:19367
CVE-2026-23868

+ RHSA-2026:19366 Important: python-markdown security update
https://access.redhat.com/errata/RHSA-2026:19366
CVE-2025-69534

+ RHSA-2026:19364 Important: dovecot security update
https://access.redhat.com/errata/RHSA-2026:19364
CVE-2025-59032
CVE-2026-27857
CVE-2026-27858

+ RHSA-2026:19365 Important: jq security update
https://access.redhat.com/errata/RHSA-2026:19365
CVE-2026-39979
CVE-2026-40164

+ RHSA-2026:19359 Important: openexr security update
https://access.redhat.com/errata/RHSA-2026:19359
CVE-2026-34588

+ RHSA-2026:19361 Moderate: glib2 security update
https://access.redhat.com/errata/RHSA-2026:19361
CVE-2025-14087
CVE-2025-14512

+ RHSA-2026:18958 Moderate: python3.12 security update
https://access.redhat.com/errata/RHSA-2026:18958
CVE-2026-0865

+ RHSA-2026:18039 Important: ruby security update
https://access.redhat.com/errata/RHSA-2026:18039
CVE-2026-41316

+ RHSA-2026:18030 Important: ruby:3.3 security update
https://access.redhat.com/errata/RHSA-2026:18030
CVE-2026-41316

+ RHSA-2026:18029 Critical: nginx security update
https://access.redhat.com/errata/RHSA-2026:18029
CVE-2026-42945

+ RHSA-2026:18028 Moderate: libpng security update
https://access.redhat.com/errata/RHSA-2026:18028
CVE-2026-33416

+ Google Chrome 148.0.7778.178/179 released
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html

+ Mozilla Firefox 151.0 released
https://www.firefox.com/en-US/firefox/151.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-46 Security Vulnerabilities fixed in Firefox 151
https://www.mozilla.org/en-US/security/advisories/mfsa2026-46/
CVE-2026-8945
CVE-2026-8946
CVE-2026-8947
CVE-2026-8948
CVE-2026-8949
CVE-2026-8950
CVE-2026-8951
CVE-2026-8952
CVE-2026-8953
CVE-2026-8954
CVE-2026-8955
CVE-2026-8956
CVE-2026-8957
CVE-2026-8958
CVE-2026-8959
CVE-2026-8960
CVE-2026-8961
CVE-2026-8962
CVE-2026-8963
CVE-2026-8964
CVE-2026-8965
CVE-2026-8966
CVE-2026-8967
CVE-2026-8968
CVE-2026-8969
CVE-2026-8970
CVE-2026-8971
CVE-2026-8972
CVE-2026-8973
CVE-2026-8974
CVE-2026-8975

+ Mozilla Foundation Security Advisory 2026-48 Security Vulnerabilities fixed in Firefox ESR 140.11
https://www.mozilla.org/en-US/security/advisories/mfsa2026-48/

+ Mozilla Foundation Security Advisory 2026-47 Security Vulnerabilities fixed in Firefox ESR 115.36
https://www.mozilla.org/en-US/security/advisories/mfsa2026-47/

+ Mozilla Foundation Security Advisory 2026-50 Security Vulnerabilities fixed in Thunderbird 151
https://www.mozilla.org/en-US/security/advisories/mfsa2026-50/

+ Mozilla Foundation Security Advisory 2026-51 Security Vulnerabilities fixed in Thunderbird 140.11
https://www.mozilla.org/en-US/security/advisories/mfsa2026-51/

+ Wireshark 4.6.6, 4.4.16 Released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.6.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.16.html

+ Linux KernelのLPE脆弱性(PinTheft: CVE未アサイン:RDSモジュール)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260520/

+ Windows Snipping Tool NTLMv2 Hash Hijack
https://cxsecurity.com/issue/WLB-2026050011
CVE-2026-33829

ネットワーク図の描き方入門 第7回
良い論理構成図を描くコツ セグメントを太線で表し、ノードを細線でつなぐ
https://xtech.nikkei.com/atcl/nxt/column/18/03451/042700007/?ST=nxt_thmit_security

JVN#03037325 エレコム製無線LANルーターおよび無線アクセスポイントにおける複数の脆弱性(2026年5月)
https://jvn.jp/jp/JVN03037325/index.html

2026年5月19日火曜日

19日 火曜日、赤口

+ Linux KernelのLPE(Local Privilege Escalation)脆弱性(Dirty Frag (CopyFail2): CVE-2026-43284, CVE-2026-43500)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260508/
CVE-2026-43284
CVE-2026-43500

VU#777338 SGLang contains two remote code execution and one path traversal vulnerability
https://www.kb.cert.org/vuls/id/777338

ネットワーク図の描き方入門 第6回
要件を整理するネットワーク図を描くコツ 登場人物や場所を先に洗い出す
https://xtech.nikkei.com/atcl/nxt/column/18/03451/042700006/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
GMO系の診療予約で障害 有効になった古い経路、管理画面にアクセス不可
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900364/?ST=nxt_thmit_security

2026年5月18日月曜日

18日 月曜日、大安

+ ■Windows DNSクライアントの脆弱性情報が公開されました(CVE-2026-41096)
https://jprs.jp/tech/security/2026-05-15-windows.html
CVE-2026-41096

+ Postfix stable release 3.11.3 and legacy releases 3.10.10, 3.9.11, 3.8.17
https://www.postfix.org/announcements/postfix-3.11.3.html

+ Linux Kernelの脆弱性(ssh-keygen-pwn: Important: CVE-2026-46333)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260517/
CVE-2026-46333

JVN#69128376 Musetheque V4 情報公開 for IPKNOWLEDGEにおける複数の脆弱性
https://jvn.jp/jp/JVN69128376/index.html

JVNVU#94687621 CISA ICS Advisory / ICS Medical Advisory(2026年05月14日)
https://jvn.jp/vu/JVNVU94687621/index.html