2026年3月25日水曜日

25日 水曜日、友引

+ RHSA-2026:5588 Moderate: python3 security update
https://access.redhat.com/errata/RHSA-2026:5588
CVE-2025-0938

+ RHSA-2026:5585 Moderate: gnutls security update
https://access.redhat.com/errata/RHSA-2026:5585
CVE-2025-9820
CVE-2025-14831

+ RHSA-2026:5587 Moderate: opencryptoki security update
https://access.redhat.com/errata/RHSA-2026:5587
CVE-2026-23893

+ RHSA-2026:5581 Moderate: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:5581
CVE-2026-1642

+ RHSA-2026:5580 Moderate: mysql:8.0 security update
https://access.redhat.com/errata/RHSA-2026:5580
CVE-2026-21936
CVE-2026-21937
CVE-2026-21941
CVE-2026-21948
CVE-2026-21964
CVE-2026-21968

+ RHSA-2026:5578 Moderate: virt:rhel and virt-devel:rhel security update
https://access.redhat.com/errata/RHSA-2026:5578
CVE-2025-11234

+ RHSA-2026:5513 Moderate: 389-ds:1.4 security update
https://access.redhat.com/errata/RHSA-2026:5513
CVE-2025-14905

+ RHSA-2026:5640 Moderate: mysql:8.4 security update
https://access.redhat.com/errata/RHSA-2026:5640
CVE-2026-21936
CVE-2026-21937
CVE-2026-21941
CVE-2026-21948
CVE-2026-21964
CVE-2026-21968

+ RHSA-2026:5599 Moderate: nginx security update
https://access.redhat.com/errata/RHSA-2026:5599
CVE-2026-1642

+ RHSA-2026:5602 Moderate: vim security update
https://access.redhat.com/errata/RHSA-2026:5602
CVE-2026-25749

+ RHSA-2026:5603 Moderate: opencryptoki security update
https://access.redhat.com/errata/RHSA-2026:5603
CVE-2026-23893

+ About the security content of iOS 26.4 and iPadOS 26.4
https://support.apple.com/en-us/126792
CVE-2026-28865
CVE-2026-28877
CVE-2026-28895
CVE-2026-28879
CVE-2026-28822
CVE-2026-28874
CVE-2026-28875
CVE-2026-28894
CVE-2026-28866
CVE-2026-20690
CVE-2026-28886
CVE-2026-28878
CVE-2025-14524
CVE-2026-28876
CVE-2026-28870
CVE-2026-28880
CVE-2026-28833
CVE-2025-64505
CVE-2026-28868
CVE-2026-28867
CVE-2026-20698
CVE-2026-20687
CVE-2026-28882
CVE-2026-20692
CVE-2026-20688
CVE-2026-28863
CVE-2026-28864
CVE-2026-28856
CVE-2026-28858
CVE-2026-28852
CVE-2026-20665
CVE-2026-20643
CVE-2026-28871
CVE-2026-20664
CVE-2026-28857
CVE-2026-28861
CVE-2026-28859
CVE-2026-20691

+ About the security content of iOS 18.7.7 and iPadOS 18.7.7
https://support.apple.com/en-us/126793

+ About the security content of macOS Tahoe 26.4
https://support.apple.com/en-us/126794

+ About the security content of macOS Sequoia 15.7.5
https://support.apple.com/en-us/126795

+ About the security content of macOS Sonoma 14.8.5
https://support.apple.com/en-us/126796

+ About the security content of tvOS 26.4
https://support.apple.com/en-us/126797

+ About the security content of watchOS 26.4
https://support.apple.com/en-us/126798

+ About the security content of visionOS 26.4
https://support.apple.com/en-us/126799

+ About the security content of Safari 26.4
https://support.apple.com/en-us/126800

+ About the security content of Xcode 26.4
https://support.apple.com/en-us/126801

+ watchOS 8.8.2, 5.3.10 released
https://support.apple.com/en-us/100100

+ Mozilla Firefox 149.0 released
https://www.firefox.com/en-US/firefox/149.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-20 Security Vulnerabilities fixed in Firefox 149
https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/
CVE-2026-4684
CVE-2026-4685
CVE-2026-4686
CVE-2026-4687
CVE-2026-4688
CVE-2026-4689
CVE-2026-4690
CVE-2026-4691
CVE-2026-4692
CVE-2026-4693
CVE-2026-4694
CVE-2026-4695
CVE-2026-4696
CVE-2026-4697
CVE-2026-4698
CVE-2026-4699
CVE-2026-4700
CVE-2026-4701
CVE-2026-4722
CVE-2026-4702
CVE-2026-4723
CVE-2026-4724
CVE-2026-4704
CVE-2026-4705
CVE-2026-4706
CVE-2026-4707
CVE-2026-4708
CVE-2026-4709
CVE-2026-4710
CVE-2026-4711
CVE-2026-4725
CVE-2026-4712
CVE-2026-4713
CVE-2026-4714
CVE-2026-4715
CVE-2026-4716
CVE-2026-4717
CVE-2026-4726
CVE-2025-59375
CVE-2026-4727
CVE-2026-4728
CVE-2026-4718
CVE-2026-4719
CVE-2026-4720
CVE-2026-4729
CVE-2026-4721

+ nginx 1.28.3, 1.29.7 released
https://nginx.org/en/CHANGES-1.28
https://nginx.org/en/CHANGES

+ Mozilla Foundation Security Advisory 2026-23 Security Vulnerabilities fixed in Thunderbird 149
https://www.mozilla.org/en-US/security/advisories/mfsa2026-23/

+ Mozilla Foundation Security Advisory 2026-24 Security Vulnerabilities fixed in Thunderbird 140.9
https://www.mozilla.org/en-US/security/advisories/mfsa2026-24/

+ Mozilla Foundation Security Advisory 2026-22 Security Vulnerabilities fixed in Firefox ESR 140.9
https://www.mozilla.org/en-US/security/advisories/mfsa2026-22/

+ Mozilla Foundation Security Advisory 2026-21 Security Vulnerabilities fixed in Firefox ESR 115.34
https://www.mozilla.org/en-US/security/advisories/mfsa2026-21/

+ Apache Tomcat 10.1.53 Released
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.53_(schultz)

VU#330121 IDrive for Windows contains local privilege escalation vulnerability
https://www.kb.cert.org/vuls/id/330121

VU#577436 Hard coded credentials vulnerability in GoHarbor's Harbor
https://www.kb.cert.org/vuls/id/577436

UPDATE: JVNVU#95523788 三菱電機数値制御装置におけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU95523788/index.html

piyokangoの月刊システムトラブル
ソリトンのFileZenに脆弱性 ウイルス検知の有効化で悪用
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/031700085/?ST=nxt_thmit_security

2026年3月24日火曜日

24日 火曜日、先勝

+ Google Chrome 146.0.7680.164/165 released
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_23.html

JVNVU#96212424 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU96212424/index.html

JVNVU#95058959 CTEK製Chargeportalにおける複数の脆弱性
https://jvn.jp/vu/JVNVU95058959/index.html

JVNVU#98951712 IGL-Technologies製eParking.fiにおける複数の脆弱性
https://jvn.jp/vu/JVNVU98951712/index.html

JVNVU#98985254 Automated Logic製WebCTRL Premium Serverにおける複数の脆弱性
https://jvn.jp/vu/JVNVU98985254/index.html

記者の眼
生成AIが「下手な鉄砲」型サイバー攻撃を増やす、足元固めを急ごう
https://xtech.nikkei.com/atcl/nxt/column/18/00138/031901981/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
小林クリエイト、データ消失原因が判明 第3報で不正アクセスを否定
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900357/?ST=nxt_thmit_security

2026年3月23日月曜日

23日 月曜日、赤口

+ RHSA-2026:5113 Important: gimp:2.8 security update
https://access.redhat.com/errata/RHSA-2026:5113
CVE-2026-0797
CVE-2026-2044
CVE-2026-2045
CVE-2026-2048

+ RHSA-2026:4952 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:4952
CVE-2025-61726
CVE-2025-61729
CVE-2025-68121

+ RHSA-2026:5080 Important: libarchive security update
https://access.redhat.com/errata/RHSA-2026:5080
CVE-2026-4111

+ RHSA-2026:4898 Important: capstone security update
https://access.redhat.com/errata/RHSA-2026:4898
CVE-2025-67873
CVE-2025-68114

+ Apache Tomcat 11.0.20, 9.0.116 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.20_(markt)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.116_(remm)

+ Linux Kernel 5.8 < 5.15.25 - Local Privilege Escalation Exploit
https://cxsecurity.com/issue/WLB-2026030029
CVE-2022-0847

JVNVU#95093977 Xerox FreeFlow Coreにおける複数の脆弱性(XRX26-005)
https://jvn.jp/vu/JVNVU95093977/index.html