2026年8月18日火曜日

18日 火曜日、赤口

+ About the security content of iOS 26.6.1 and iPadOS 26.6.1
https://support.apple.com/en-us/148282
CVE-2026-65339
CVE-2026-65347
CVE-2026-65346
CVE-2026-64788
CVE-2026-65343
CVE-2026-65349
CVE-2026-65330
CVE-2026-65329
CVE-2026-64784
CVE-2026-43795
CVE-2026-65338
CVE-2026-65341
CVE-2026-64782
CVE-2026-64781
CVE-2026-65351
CVE-2026-65340
CVE-2026-65337
CVE-2026-65336
CVE-2026-65335
CVE-2026-65333
CVE-2026-65332
CVE-2026-65331
CVE-2026-64715
CVE-2026-64780
CVE-2026-65334
CVE-2026-43794
CVE-2026-64787
CVE-2026-64778
CVE-2026-64779

+ About the security content of iOS 18.7.10 and iPadOS 18.7.10
https://support.apple.com/en-us/148287

+ About the security content of macOS Tahoe 26.6.2
https://support.apple.com/en-us/148281

+ visionOS 26.6.1 released
https://support.apple.com/en-us/100100

記者の眼
「不正アクセス」に他責の響き、ニュースリリースがぼかす管理不備
https://xtech.nikkei.com/atcl/nxt/column/18/00138/081402080/?ST=nxt_thmit_security

未成年保護から選挙対策まで、世界で強まるSNS規制 第2回
米豪のSNS規制、若年層への情報発信に壁 日本企業は広報戦略見直しも
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
Eストアーで885万件超漏洩、配送先や店舗のFTPパスワードも対象
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900377/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋 第2回
価格や日本語対応だけではない、国産セキュリティーが選ばれる強み
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080700004/?ST=nxt_thmit_security

JVN#58692577 F-RevoCRMにおけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN58692577/index.html

JVN#40688603 miCheckerにおけるXML外部実体参照(XXE)に関する脆弱性
https://jvn.jp/jp/JVN40688603/index.html

JVN#91713656 Synology Assistantにおける不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN91713656/index.html

2026年8月17日月曜日

17日 月曜日、大安

+ ■Windows DNSの脆弱性情報が公開されました(CVE-2026-70330、他15件)
https://jprs.jp/tech/security/2026-08-14-windows.html

+ PuTTY 0.85 released
https://www.chiark.greenend.org.uk/~sgtatham/putty/releases/0.85.html

+ S2-070 All Struts 2 developers and users of the JSON plugin
https://cwiki.apache.org/confluence/spaces/WW/pages/444334417/S2-070
CVE-2026-73631

+ S2-071 All Struts 2 developers and users of the JSON plugin
https://cwiki.apache.org/confluence/spaces/WW/pages/444334419/S2-071
CVE-2026-73632

+ S2-073 Struts 2 developers and users whose applications expose an endpoint collecting Content Security Policy violation reports
https://cwiki.apache.org/confluence/spaces/WW/pages/444334431/S2-073
CVE-2026-73634

+ S2-074 All Struts 2 developers and users
https://cwiki.apache.org/confluence/spaces/WW/pages/444334689/S2-074
CVE-2026-73635

+ ProFTPD 1.3.9d released
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.9d
http://www.proftpd.org/docs/NEWS-1.3.9d

+ Apache Strutsの脆弱性(Moderate: CVE-2026-73631, CVE-2026-73633, CVE-2026-73634, CVE-2026-73635, Low: CVE-2026-73632)
https://security.sios.jp/vulnerability/struts-security-vulnerability-20260814/
CVE-2026-73631
CVE-2026-73633
CVE-2026-73634
CVE-2026-73635
CVE-2026-73632

JVN#40688603 miCheckerにおけるXML外部実体参照(XXE)に関する脆弱性
https://jvn.jp/jp/JVN40688603/index.html

JVN#91713656 Synology Assistantにおける不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN91713656/index.html

JVNVU#97860021 CISA ICS Advisory / ICS Medical Advisory(2026年08月13日)
https://jvn.jp/vu/JVNVU97860021/index.html

未成年保護から選挙対策まで、世界で強まるSNS規制 第1回
EUのSNS規制、日本企業にも波及 未成年保護で広告とUIに制約
https://xtech.nikkei.com/atcl/nxt/column/18/03714/080500001/?ST=nxt_thmit_security

海外依存を抜け出せ、国産セキュリティー製品の勝ち筋 第1回
海外製品が止まっても日本を守る、国産セキュリティー振興の全貌を徹底解説
https://xtech.nikkei.com/atcl/nxt/column/18/03715/080600001/?ST=nxt_thmit_security

2026年8月14日金曜日

14日 金曜日、友引

+ RHSA-2026:54654 Important: bind security update
https://access.redhat.com/errata/RHSA-2026:54654
CVE-2026-10723
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54575 Important: dracut security update
https://access.redhat.com/errata/RHSA-2026:54575
CVE-2026-15816

+ RHSA-2026:54542 Important: .NET 10.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:54542
CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

+ RHSA-2026:54538 Important: .NET 8.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:54538
CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62909

+ RHSA-2026:54509 Important: bind9.16 security update
https://access.redhat.com/errata/RHSA-2026:54509
CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54485 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:54485
CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

+ RHSA-2026:54662 Moderate: nghttp2 security update
https://access.redhat.com/errata/RHSA-2026:54662
CVE-2026-58055

+ RHSA-2026:54571 Important: dracut security update
https://access.redhat.com/errata/RHSA-2026:54571
CVE-2026-15816

+ RHSA-2026:54510 Important: bind security update
https://access.redhat.com/errata/RHSA-2026:54510
CVE-2026-10723
CVE-2026-11331
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

+ RHSA-2026:54487 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:54487
CVE-2026-64624
CVE-2026-67289
CVE-2026-67299
CVE-2026-68580

+ RHSA-2026:54484 Moderate: python-idna security update
https://access.redhat.com/errata/RHSA-2026:54484
CVE-2026-45409

+ Microsoft Drivers for PHP for SQL Server 5.13.2 released
https://learn.microsoft.com/ja-jp/sql/connect/php/download-drivers-php-sql-server?view=sql-server-ver17

+ UPDATE: Oracle Critical Patch Update Advisory - July 2026
https://www.oracle.com/security-alerts/cpujul2026.html

+ Unbounded Memory Growth in QUIC Server Incoming Channel Queue
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-14456
CVE-2026-14456

+ PostgreSQL 18.6, 17.11, 16.15, 15.19, 14.24 and 19 Beta 3 Released!
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
https://www.postgresql.org/docs/18/release-18-6.html
https://www.postgresql.org/docs/17/release-17-11.html
https://www.postgresql.org/docs/16/release-16-15.html
https://www.postgresql.org/docs/15/release-15-19.html
https://www.postgresql.org/docs/14/release-14-24.html

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
ランサムウエア攻撃者の侵入経路 脆弱性悪用を抜きメールが首位に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/080500192/?ST=nxt_thmit_security

JVN#00941257 VoiceTraにおける接続先の制限が不適切な脆弱性
https://jvn.jp/jp/JVN00941257/index.html