2026年8月19日水曜日

19日 水曜日、先勝

+ RHSA-2026:56521 Important: gstreamer1-plugins-bad-free security update
https://access.redhat.com/errata/RHSA-2026:56521
CVE-2026-19387

+ RHSA-2026:56219 Important: python3 security update
https://access.redhat.com/errata/RHSA-2026:56219
CVE-2026-11940

+ RHSA-2026:56131 Moderate: pam security update
https://access.redhat.com/errata/RHSA-2026:56131
CVE-2026-54411

+ RHSA-2026:56133 Moderate: attr security update
https://access.redhat.com/errata/RHSA-2026:56133
CVE-2026-54371

+ RHSA-2026:56130 Important: sg3_utils security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:56130
CVE-2026-16313

+ RHSA-2026:55764 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:55764
CVE-2025-39902
CVE-2026-17523
CVE-2026-43206
CVE-2026-53016
CVE-2026-53136
CVE-2026-53329
CVE-2026-53374
CVE-2026-63879
CVE-2026-63884
CVE-2026-64219

+ RHSA-2026:55560 Important: pcp security update
https://access.redhat.com/errata/RHSA-2026:55560
CVE-2026-16524
CVE-2026-16526
CVE-2026-16527
CVE-2026-16529

+ RHSA-2026:55530 Important: 389-ds:1.4 security update
https://access.redhat.com/errata/RHSA-2026:55530
CVE-2026-11770
CVE-2026-11788
CVE-2026-15722

+ RHSA-2026:55865 Important: gstreamer1-plugins-bad-free and gstreamer1-plugins-ugly-free security update
https://access.redhat.com/errata/RHSA-2026:55865
CVE-2026-19387
CVE-2026-19389

+ RHSA-2026:55841 Important: unbound security update
https://access.redhat.com/errata/RHSA-2026:55841
CVE-2026-44690
CVE-2026-55973

+ RHSA-2026:55772 Important: haproxy security update
https://access.redhat.com/errata/RHSA-2026:55772
CVE-2026-55203
CVE-2026-55204

+ RHSA-2026:55763 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:55763
CVE-2026-43038
CVE-2026-43125
CVE-2026-43329
CVE-2026-46244
CVE-2026-64530

+ RHSA-2026:55603 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:55603
CVE-2026-11822
CVE-2026-11824
CVE-2026-14257
CVE-2026-54272
CVE-2026-69152
CVE-2026-69192

+ RHSA-2026:55601 Important: nodejs:22 security update
https://access.redhat.com/errata/RHSA-2026:55601
CVE-2026-11822
CVE-2026-11824
CVE-2026-14257
CVE-2026-69152
CVE-2026-69192

+ About the security content of Safari 26.6.1
https://support.apple.com/en-us/148286
CVE-2026-64784
CVE-2026-43795
CVE-2026-65338
CVE-2026-65341
CVE-2026-64782
CVE-2026-64781
CVE-2026-65351
CVE-2026-65340
CVE-2026-65337
CVE-2026-65336
CVE-2026-65335
CVE-2026-65333
CVE-2026-65332
CVE-2026-65331
CVE-2026-64715
CVE-2026-64780
CVE-2026-65334
CVE-2026-43794
CVE-2026-64787
CVE-2026-64778
CVE-2026-64779

+ Google Chrome 151.0.7922.169/.170, 150.0.7871.250 released
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html
https://chromereleases.googleblog.com/2026/08/extended-stable-update-for-desktop_01726425345.html

+ Mozilla Firefox 154.0 released
https://www.firefox.com/en-US/firefox/154.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-74 Security Vulnerabilities fixed in Firefox 154
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/
CVE-2026-75874
CVE-2026-74934
CVE-2026-74935
CVE-2026-74936
CVE-2026-74937
CVE-2026-74938
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74943
CVE-2026-74944
CVE-2026-74945
CVE-2026-74946
CVE-2026-74947
CVE-2026-74948
CVE-2026-74949
CVE-2026-74950
CVE-2026-74951
CVE-2026-74952
CVE-2026-74953
CVE-2026-74954
CVE-2026-74955
CVE-2026-74956
CVE-2026-74957
CVE-2026-74958
CVE-2026-74959
CVE-2026-74960
CVE-2026-74961
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74966
CVE-2026-74967
CVE-2026-74968
CVE-2026-74969
CVE-2026-74970
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74975
CVE-2026-74976
CVE-2026-74977
CVE-2026-74978
CVE-2026-74979
CVE-2026-74980
CVE-2026-74981
CVE-2026-74982
CVE-2026-74983
CVE-2026-74984
CVE-2026-74985
CVE-2026-74986
CVE-2026-74987
CVE-2026-74988
CVE-2026-74989
CVE-2026-74990

+ Mozilla Thunderbird 154.0 released
https://www.thunderbird.net/en-US/thunderbird/154.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-78 Security Vulnerabilities fixed in Thunderbird 154
https://www.mozilla.org/en-US/security/advisories/mfsa2026-78/

+ Mozilla Foundation Security Advisory 2026-77 Security Vulnerabilities fixed in Firefox ESR 153.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/

+ Mozilla Foundation Security Advisory 2026-76 Security Vulnerabilities fixed in Firefox ESR 140.14
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/

+ Mozilla Foundation Security Advisory 2026-75 Security Vulnerabilities fixed in Firefox ESR 115.39
https://www.mozilla.org/en-US/security/advisories/mfsa2026-75/

+ Mozilla Foundation Security Advisory 2026-80 Security Vulnerabilities fixed in Thunderbird 153.1
https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/

+ Mozilla Foundation Security Advisory 2026-79 Security Vulnerabilities fixed in Thunderbird 140.14
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/

+ Apache Tomcat 11.0.25, 9.0.121 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.25_(markt)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.121_(remm)

+ Linux Kernelの脆弱性(CVE-2026-68081~CVE-2026-68479)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20260819/

JVN#06609828 Apache Alluraにおけるサーバサイドリクエストフォージェリの脆弱性
https://jvn.jp/jp/JVN06609828/index.html

勝村幸博の「今日も誰かが狙われる」
ホテルからのMicrosoft 365利用が危ない、公衆Wi-Fi機器への侵害を警告
https://xtech.nikkei.com/atcl/nxt/column/18/00676/080600231/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋
国内に軸足、海外の拠点や人材を生かす国産セキュリティーの現実解
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080700005/?ST=nxt_thmit_security

未成年保護から選挙対策まで、世界で強まるSNS規制 第3回
選挙偽情報対策で法改正、企業SNS運用に投稿・拡散の新リスク
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500003/?ST=nxt_thmit_security

2026年8月18日火曜日

18日 火曜日、赤口

+ About the security content of iOS 26.6.1 and iPadOS 26.6.1
https://support.apple.com/en-us/148282
CVE-2026-65339
CVE-2026-65347
CVE-2026-65346
CVE-2026-64788
CVE-2026-65343
CVE-2026-65349
CVE-2026-65330
CVE-2026-65329
CVE-2026-64784
CVE-2026-43795
CVE-2026-65338
CVE-2026-65341
CVE-2026-64782
CVE-2026-64781
CVE-2026-65351
CVE-2026-65340
CVE-2026-65337
CVE-2026-65336
CVE-2026-65335
CVE-2026-65333
CVE-2026-65332
CVE-2026-65331
CVE-2026-64715
CVE-2026-64780
CVE-2026-65334
CVE-2026-43794
CVE-2026-64787
CVE-2026-64778
CVE-2026-64779

+ About the security content of iOS 18.7.10 and iPadOS 18.7.10
https://support.apple.com/en-us/148287

+ About the security content of macOS Tahoe 26.6.2
https://support.apple.com/en-us/148281

+ visionOS 26.6.1 released
https://support.apple.com/en-us/100100

記者の眼
「不正アクセス」に他責の響き、ニュースリリースがぼかす管理不備
https://xtech.nikkei.com/atcl/nxt/column/18/00138/081402080/?ST=nxt_thmit_security

未成年保護から選挙対策まで、世界で強まるSNS規制 第2回
米豪のSNS規制、若年層への情報発信に壁 日本企業は広報戦略見直しも
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
Eストアーで885万件超漏洩、配送先や店舗のFTPパスワードも対象
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900377/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋 第2回
価格や日本語対応だけではない、国産セキュリティーが選ばれる強み
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080700004/?ST=nxt_thmit_security

JVN#58692577 F-RevoCRMにおけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN58692577/index.html

JVN#40688603 miCheckerにおけるXML外部実体参照(XXE)に関する脆弱性
https://jvn.jp/jp/JVN40688603/index.html

JVN#91713656 Synology Assistantにおける不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN91713656/index.html

2026年8月17日月曜日

17日 月曜日、大安

+ ■Windows DNSの脆弱性情報が公開されました(CVE-2026-70330、他15件)
https://jprs.jp/tech/security/2026-08-14-windows.html

+ PuTTY 0.85 released
https://www.chiark.greenend.org.uk/~sgtatham/putty/releases/0.85.html

+ S2-070 All Struts 2 developers and users of the JSON plugin
https://cwiki.apache.org/confluence/spaces/WW/pages/444334417/S2-070
CVE-2026-73631

+ S2-071 All Struts 2 developers and users of the JSON plugin
https://cwiki.apache.org/confluence/spaces/WW/pages/444334419/S2-071
CVE-2026-73632

+ S2-073 Struts 2 developers and users whose applications expose an endpoint collecting Content Security Policy violation reports
https://cwiki.apache.org/confluence/spaces/WW/pages/444334431/S2-073
CVE-2026-73634

+ S2-074 All Struts 2 developers and users
https://cwiki.apache.org/confluence/spaces/WW/pages/444334689/S2-074
CVE-2026-73635

+ ProFTPD 1.3.9d released
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.9d
http://www.proftpd.org/docs/NEWS-1.3.9d

+ Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632)
https://security.sios.jp/vulnerability/struts-security-vulnerability-20260814/
CVE-2026-73631
CVE-2026-73633
CVE-2026-73634
CVE-2026-73635
CVE-2026-73632

JVN#40688603 miCheckerにおけるXML外部実体参照(XXE)に関する脆弱性
https://jvn.jp/jp/JVN40688603/index.html

JVN#91713656 Synology Assistantにおける不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN91713656/index.html

JVNVU#97860021 CISA ICS Advisory / ICS Medical Advisory(2026年08月13日)
https://jvn.jp/vu/JVNVU97860021/index.html

未成年保護から選挙対策まで、世界で強まるSNS規制 第1回
EUのSNS規制、日本企業にも波及 未成年保護で広告とUIに制約
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500001/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋 第1回
海外製品が止まっても日本を守る、国産セキュリティー振興の全貌を徹底解説
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080600001/?ST=nxt_thmit_security