2026年9月10日木曜日

10日 木曜日、大安

+ RHSA-2026:66248 Important: ansible-core security update
https://access.redhat.com/errata/RHSA-2026:66248
CVE-2026-11332

+ RHSA-2026:66016 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:66016
CVE-2024-9355
CVE-2024-45336
CVE-2026-33818
CVE-2026-39820
CVE-2026-39821
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:66000 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:66000
CVE-2026-43493
CVE-2026-53002
CVE-2026-64007
CVE-2026-64563
CVE-2026-68343
CVE-2026-72129
CVE-2026-74480

+ RHSA-2026:65998 Moderate: gzip security update
https://access.redhat.com/errata/RHSA-2026:65998
CVE-2026-41991
CVE-2026-41992

+ RHSA-2026:65897 Important: qt5-qtbase security update
https://access.redhat.com/errata/RHSA-2026:65897
CVE-2026-9499

+ RHSA-2026:65832 Important: mrtg security update
https://access.redhat.com/errata/RHSA-2026:65832
CVE-2026-72694

+ RHSA-2026:66204 Important: python-lxml security update
https://access.redhat.com/errata/RHSA-2026:66204
CVE-2026-49825

+ RHSA-2026:66203 Important: python3.12-lxml security update
https://access.redhat.com/errata/RHSA-2026:66203
CVE-2026-49825

+ RHSA-2026:66179 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:66179
CVE-2026-19546

+ RHSA-2026:65993 Important: qt5-qtbase security update
https://access.redhat.com/errata/RHSA-2026:65993
CVE-2026-9499

+ RHSA-2026:65886 Important: image-builder security update
https://access.redhat.com/errata/RHSA-2026:65886
CVE-2026-32280
CVE-2026-32281
CVE-2026-33811
CVE-2026-33818
CVE-2026-39820
CVE-2026-39821
CVE-2026-42499
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ Google Chrome 154.0.8037.17/.18, 152.0.7977.120 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_01157104879.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop.html

+ Mozill Thunderbird 155.0.1 released
https://www.thunderbird.net/en-US/thunderbird/155.0.1/releasenotes/

JVN#21088484 baserCMS用プラグイン「BurgerEditor」における複数の脆弱性
https://jvn.jp/jp/JVN21088484/index.html

JVNVU#93257103 CISA ICS Advisory / ICS Medical Advisory(2026年09月08日)
https://jvn.jp/vu/JVNVU93257103/index.html

JVNVU#94974158 SPI Flashに組み込まれたUEFI Shellモジュールにおけるセキュアブート回避の脆弱性
https://jvn.jp/vu/JVNVU94974158/index.html

JVNVU#94533753 Ascensio System SIA製ONLYOFFICE ownCloud統合プラグインにおけるサーバサイドリクエストフォージェリの脆弱性
https://jvn.jp/vu/JVNVU94533753/index.html

JVNVU#91877671 Skullcandy製ワイヤレスイヤホン「Dime 3」における不適切な認証の脆弱性
https://jvn.jp/vu/JVNVU91877671/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

2026年9月9日水曜日

9日 水曜日、仏滅

+ RHSA-2026:65160 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:65160
CVE-2026-74934
CVE-2026-74935
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74945
CVE-2026-74946
CVE-2026-74948
CVE-2026-74953
CVE-2026-74957
CVE-2026-74959
CVE-2026-74960
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74967
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74976
CVE-2026-74987
CVE-2026-74990

+ RHSA-2026:65147 Important: microcode_ctl security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:65147
CVE-2025-31936
CVE-2025-35973

+ RHSA-2026:64823 Important: redis:6 security update
https://access.redhat.com/errata/RHSA-2026:64823
CVE-2026-66373
CVE-2026-81934

+ RHSA-2026:65606 Important: gpsd-minimal security update
https://access.redhat.com/errata/RHSA-2026:65606
CVE-2026-60122

+ RHSA-2026:65117 Important: opentelemetry-collector security update
https://access.redhat.com/errata/RHSA-2026:65117
CVE-2026-33818
CVE-2026-39820
CVE-2026-41178
CVE-2026-42499
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:64824 Important: redis security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:64824
CVE-2026-66373
CVE-2026-81934

+ RHSA-2026:64774 Important: python3.14-cryptography security update
https://access.redhat.com/errata/RHSA-2026:64774
CVE-2026-69248
CVE-2026-69249

+ iOS 26.6.2 and iPadOS 26.6.2 released
https://support.apple.com/en-us/100100

+ Google Chrome 153.0.8010.36/.37 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html

+ FreeBSD 14.5-RELEASE released
https://www.freebsd.org/releases/14.5R/relnotes/

+ Apache Tomcat Native 2.0.16, 1.3.9 released
https://tomcat.apache.org/native-doc/miscellaneous/changelog.html#2.0.16
https://tomcat.apache.org/native-1.3-doc/miscellaneous/changelog.html#1.3.9

+ OpenLDAP-2.7.1, 2.6.15 released
https://www.openldap.org/software/release/changes.html
https://www.openldap.org/software/release/changes_lts.html

+ Postfix stable release 3.11.7 and legacy releases 3.10.14, 3.9.15, 3.8.21, 3.7.23, 3.6.21, 3.5.28 released
https://www.postfix.org/announcements/postfix-3.11.7.html

■Knot DNSの脆弱性情報が公開されました
https://jprs.jp/tech/security/2026-09-08-knotdns.html

VU#718077 UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
https://www.kb.cert.org/vuls/id/718077

VU#859658 Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
https://www.kb.cert.org/vuls/id/859658

VU#943094 ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
https://www.kb.cert.org/vuls/id/943094

ニュース解説
スマホで法人代表者の実印、「商業登記リモート署名」開始 民間と競合も
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12018/?ST=nxt_thmit_security

全日空商事「選べるe-GIFT」で不正交換、管理システムに第三者がアクセス
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900380/?ST=nxt_thmit_security

2026年9月7日月曜日

7日 月曜日、友引

+ Mozilla Firefox 155.0.1 released
https://www.firefox.com/en-US/firefox/155.0.1/releasenotes/

+ Apache Ant 1.10.18 Released
https://ant.apache.org/bindownload.cgi

+ Windows Defender (MsMpEng.exe) Race Condition
https://cxsecurity.com/issue/WLB-2026090007

+ ProFTPD mod_sql post-authentication SQLi RCE
https://cxsecurity.com/issue/WLB-2026090006
CVE-2026-42167

JVN#32505330 エクシングCPTrans-ME-Xにおける複数の脆弱性
https://jvn.jp/jp/JVN32505330/index.html

JVNVU#94249914 CISA ICS Advisory / ICS Medical Advisory(2026年09月03日)
https://jvn.jp/vu/JVNVU94249914/index.html

JVNVU#96680494 Casdoorにおける認可回避の脆弱性
https://jvn.jp/vu/JVNVU96680494/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html