2026年9月7日月曜日

7日 月曜日、友引

+ Mozilla Firefox 155.0.1 released
https://www.firefox.com/en-US/firefox/155.0.1/releasenotes/

+ Apache Ant 1.10.18 Released
https://ant.apache.org/bindownload.cgi

+ Windows Defender (MsMpEng.exe) Race Condition
https://cxsecurity.com/issue/WLB-2026090007

+ ProFTPD mod_sql post-authentication SQLi RCE
https://cxsecurity.com/issue/WLB-2026090006
CVE-2026-42167

JVN#32505330 エクシングCPTrans-ME-Xにおける複数の脆弱性
https://jvn.jp/jp/JVN32505330/index.html

JVNVU#94249914 CISA ICS Advisory / ICS Medical Advisory(2026年09月03日)
https://jvn.jp/vu/JVNVU94249914/index.html

JVNVU#96680494 Casdoorにおける認可回避の脆弱性
https://jvn.jp/vu/JVNVU96680494/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

2026年9月4日金曜日

4日 金曜日、大安

+ domain-scoped PSL domain cookie
https://curl.se/docs/CVE-2026-82209.html
CVE-2026-82209

+ wolfSSL CA-cache hit overrides callback
https://curl.se/docs/CVE-2026-82208.html
CVE-2026-82208

+ secure cookie attribute bypass with tab
https://curl.se/docs/CVE-2026-80255.html
CVE-2026-80255

+ native CA store conn reuse
https://curl.se/docs/CVE-2026-80231.html
CVE-2026-80231

+ OpenSSL pinning bypass
https://curl.se/docs/CVE-2026-80230.html
CVE-2026-80230

+ OpenSSL provider use-after-free
https://curl.se/docs/CVE-2026-80229.html
CVE-2026-80229

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ HTTP/2 server push UAF
https://curl.se/docs/CVE-2026-18924.html
CVE-2026-18924

+ OpenLDAP SASL authentication bypass
https://curl.se/docs/CVE-2026-13608.html
CVE-2026-13608

+ RHSA-2026:63124 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63124
CVE-2026-33818
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63014 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:63014
CVE-2024-57849
CVE-2025-71132
CVE-2026-45970
CVE-2026-53185
CVE-2026-53391
CVE-2026-53392
CVE-2026-53397
CVE-2026-53399
CVE-2026-63800
CVE-2026-64018
CVE-2026-64268
CVE-2026-64298
CVE-2026-68480
CVE-2026-74581

+ RHSA-2026:63387 Important: Satellite 6.17.11 Async Update
https://access.redhat.com/errata/RHSA-2026:63387
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63386 Important: Satellite 6.18.9 Async Update
https://access.redhat.com/errata/RHSA-2026:63386
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63136 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63136
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63130 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:63130
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ Google Chrome 153.0.8010.27/.28, 152.0.7977.82/.83 relased
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop.html
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html

+ UPDATE: JVNVU#96149019 Apache Tomcatにおける複数の脆弱性(2026年8月25日)
https://jvn.jp/vu/JVNVU96149019/index.html

+ UPDATE: JVNVU#96558110 OpenSSLにおける脆弱性に対するアップデート(2026年8月25日)
https://jvn.jp/vu/JVNVU96558110/index.html

+ UPDATE: JVNVU#92139835 OpenSSLのOCSPレスポンス検証におけるクライアント側のメモリリークの脆弱性(CVE-2026-54876)
https://jvn.jp/vu/JVNVU92139835/index.html

+ UPDATE: JVNVU#99139115 Apache TomcatのWebSocket chatサンプルにおけるサービス運用妨害(DoS)の脆弱性(2026年7月28日)
https://jvn.jp/vu/JVNVU99139115/index.html

+ UPDATE: JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html

+ UPDATE: JVNVU#95286373 Apache Tomcatにおける複数の脆弱性(2026年7月14日)
https://jvn.jp/vu/JVNVU95286373/index.html

VU#889462 Casdoor authentication server is vulnerable to authorization bypass
https://www.kb.cert.org/vuls/id/889462

2026年9月3日木曜日

3日 木曜日、仏滅

+ RHSA-2026:62667 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:62667
CVE-2026-9698
CVE-2026-10879
CVE-2026-14380
CVE-2026-14739

+ RHSA-2026:62583 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:62583
CVE-2026-56846
CVE-2026-56848
CVE-2026-58043

+ RHSA-2026:62571 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:62571
CVE-2026-55194
CVE-2026-67288
CVE-2026-67291
CVE-2026-67301

+ RHSA-2026:62507 Important: gimp:2.8 security update
https://access.redhat.com/errata/RHSA-2026:62507
CVE-2026-18301
CVE-2026-18303
CVE-2026-18304
CVE-2026-18305
CVE-2026-18306
CVE-2026-18307
CVE-2026-58380
CVE-2026-66758

+ RHSA-2026:62425 Important: gegl security update
https://access.redhat.com/errata/RHSA-2026:62425
CVE-2026-18300

+ RHSA-2026:62420 Important: gegl04 security update
https://access.redhat.com/errata/RHSA-2026:62420
CVE-2026-18300

+ RHSA-2026:62407 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:62407
CVE-2026-33818
CVE-2026-39820
CVE-2026-42499
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:62334 Important: php:7.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:62334
CVE-2026-7260
CVE-2026-17543

+ RHSA-2026:62144 Moderate: wget security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:62144
CVE-2026-58469
CVE-2026-58471
CVE-2026-58472

+ RHSA-2026:62640 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:62640
CVE-2026-43112
CVE-2026-43114
CVE-2026-46323
CVE-2026-52973
CVE-2026-53264

+ RHSA-2026:62217 Moderate: libssh security update
https://access.redhat.com/errata/RHSA-2026:62217
CVE-2026-59843
CVE-2026-59844
CVE-2026-59845
CVE-2026-59846
CVE-2026-59847
CVE-2026-59848
CVE-2026-59850

+ RHSA-2026:61903 Important: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:61903
CVE-2026-7260
CVE-2026-17543

+ nginx 1.31.5 released
https://nginx.org/en/CHANGES

+ Mozilla Thunderbrid 155.0 released
https://www.thunderbird.net/en-US/thunderbird/155.0/releasenotes/

ニュース&リポート
オープンAIが先端AIの安全対策緩和 中国モデルの台頭に危機感
サイバー防御プログラム拡充、一部の個人・組織に提供
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/082701491/?ST=nxt_thmit_security

NECがAnthropicの「Mythos」利用権、社内の脆弱性管理に活用
https://xtech.nikkei.com/atcl/nxt/news/24/03370/?ST=nxt_thmit_security

JVNVU#98062224 キーエンス製XG VisionTerminalおよびXG-X VisionTerminalにおけるにおけるXML外部エンティティ参照(XXE)の不適切な制限の脆弱性
https://jvn.jp/vu/JVNVU98062224/index.html

JVN#91715694 ShizenBox2における複数の脆弱性
https://jvn.jp/jp/JVN91715694/index.html

JVNVU#97909245 Hugging Face製Transformersにおけるユーザー同意確認前のリモートコード不正キャッシュの脆弱性
https://jvn.jp/vu/JVNVU97909245/index.html

JVNVU#90253159 CISA ICS Advisory / ICS Medical Advisory(2026年09月01日)
https://jvn.jp/vu/JVNVU90253159/index.html