2026年9月21日月曜日

21日 月曜日、赤口

+ RHSA-2026:69095 Important: libtiff security update
https://access.redhat.com/errata/RHSA-2026:69095
CVE-2026-52490

+ RHSA-2026:69100 Important: gstreamer1-plugins-base security update
https://access.redhat.com/errata/RHSA-2026:69100
CVE-2026-18297
CVE-2026-85150

+ JVNVU#97703430 ISC BINDにおける複数の脆弱性(2026年9月)
https://jvn.jp/vu/JVNVU97703430/index.html
CVE-2026-19033
CVE-2026-19662
CVE-2026-19666
CVE-2026-19667
CVE-2026-19668
CVE-2026-19941
CVE-2026-75029
CVE-2026-76163
CVE-2026-77119
CVE-2026-77692
CVE-2026-78301
CVE-2026-80274
CVE-2026-81563
CVE-2026-81736

2026年9月18日金曜日

18日 金曜日、先負

+ RHSA-2026:68787 Important: perl-Net-DNS security update
https://access.redhat.com/errata/RHSA-2026:68787
CVE-2026-81928

+ RHSA-2026:68676 Important: .NET 10.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68676
CVE-2026-58649
CVE-2026-69806

+ RHSA-2026:68549 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:68549
CVE-2026-16365
CVE-2026-75874
CVE-2026-84119
CVE-2026-84120
CVE-2026-84121
CVE-2026-84122
CVE-2026-84124
CVE-2026-84131
CVE-2026-84143
CVE-2026-84145

+ RHSA-2026:68660 Moderate: tomcat security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68660
CVE-2026-32990
CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43515
CVE-2026-59083
CVE-2026-59084

+ Google Chrome 153.0.8010.52/.53, 152.0.7977.134 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop_0130771745.html

AlmaLinux 9.9 Beta Now Available!
https://almalinux.org/blog/2026-09-17-announcing-99-beta/

VU#280377 Dokploy is vulnerable to OS command injection
https://www.kb.cert.org/vuls/id/280377

ITが危ない
「ダークパターン」に法規制の動き、悪質な勧誘や解約妨害は業務停止命令も
https://xtech.nikkei.com/atcl/nxt/column/18/00989/091400220/?ST=nxt_thmit_security

SCSKが伴走型セキュリティーサービス開始、生成AIで増える脅威へ備え
https://xtech.nikkei.com/atcl/nxt/news/24/03389/?ST=nxt_thmit_security

JVN#93985674 スマートフォンアプリ「東北電力 よりそうeねっと」におけるハードコードされた暗号鍵使用の脆弱性
https://jvn.jp/jp/JVN93985674/index.html

JVNVU#94390979 MLflowのdspyとstatsmodelsフレーバーにおけるpickleのデシリアライズ制御回避の脆弱性
https://jvn.jp/vu/JVNVU94390979/index.html

JVNVU#91019649 Sentry Seerにおける攻撃者が制御する入力が管理者権限で実行される脆弱性
https://jvn.jp/vu/JVNVU91019649/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

2026年9月17日木曜日

17日 木曜日、友引

+ RHSA-2026:68316 Moderate: .NET 8.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68316
CVE-2026-58649

+ RHSA-2026:68233 Important: .NET 9.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68233
CVE-2026-58649
CVE-2026-69806

+ RHSA-2026:67943 Important: python-lxml security update
https://access.redhat.com/errata/RHSA-2026:67943
CVE-2026-49825

+ RHSA-2026:67908 Important: libevent security update
https://access.redhat.com/errata/RHSA-2026:67908
CVE-2026-63382
CVE-2026-63383
CVE-2026-63384
CVE-2026-63385
CVE-2026-63387
CVE-2026-63388

+ RHSA-2026:67832 Important: tesseract security update
https://access.redhat.com/errata/RHSA-2026:67832
CVE-2026-73066

+ Google Chrome 154.0.8037.44/.45 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_096324202.html

+ Mozilla Foundation Security Advisory 2026-96 Security Vulnerabilities fixed in Thunderbird 153.3
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/

+ ISC BIND 9.21.26, 9.20.29 released
https://downloads.isc.org/isc/bind9/9.21.26/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/notes.html

+ BIND 9の脆弱性(High: CVE-2026-19666, CVE-2026-19667, CVE-2026-76163, CVE-2026-77692, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736, Medium: CVE-2026-19033, CVE-2026-19662, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-77119, CVE-2026-78301)と修正バージョン(9.20.29, 9.21.26)
https://security.sios.jp/vulnerability/bind9-security-vulnerability-20260917/
CVE-2026-19666
CVE-2026-19667
CVE-2026-76163
CVE-2026-77692
CVE-2026-80274
CVE-2026-81563
CVE-2026-81736
CVE-2026-19033
CVE-2026-19662
CVE-2026-19668
CVE-2026-19941
CVE-2026-75029
CVE-2026-77119
CVE-2026-78301

VU#369093 MLflow dspy and statsmodels flavors bypass pickle deserialization control
https://www.kb.cert.org/vuls/id/369093

VU#212479 Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
https://www.kb.cert.org/vuls/id/212479

ニュース&リポート
SBOM最小要素、26年版で増加 日本では「推奨」、強制せず
作成負荷増も、運用の自動化にはメリット
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/091001497/?ST=nxt_thmit_security

生成AI時代のOSS危機 第4回
OSSのAI再実装は悪か、波紋呼ぶ「ライセンス洗浄」と貢献の行方
https://xtech.nikkei.com/atcl/nxt/column/18/03754/091100003/?ST=nxt_thmit_security

JVN#95825631 QNDにおける複数の脆弱性
https://jvn.jp/jp/JVN95825631/index.html

JVN#45281119 XikeStor製Layer3スイッチのコンフィグレーションデータダウンロード機能における認証欠如の脆弱性
https://jvn.jp/jp/JVN45281119/index.html

JVNVU#93448623 CISA ICS Advisory / ICS Medical Advisory(2026年09月15日)
https://jvn.jp/vu/JVNVU93448623/index.html