2026年9月9日水曜日

9日 水曜日、仏滅

+ RHSA-2026:65160 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:65160
CVE-2026-74934
CVE-2026-74935
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74945
CVE-2026-74946
CVE-2026-74948
CVE-2026-74953
CVE-2026-74957
CVE-2026-74959
CVE-2026-74960
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74967
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74976
CVE-2026-74987
CVE-2026-74990

+ RHSA-2026:65147 Important: microcode_ctl security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:65147
CVE-2025-31936
CVE-2025-35973

+ RHSA-2026:64823 Important: redis:6 security update
https://access.redhat.com/errata/RHSA-2026:64823
CVE-2026-66373
CVE-2026-81934

+ RHSA-2026:65606 Important: gpsd-minimal security update
https://access.redhat.com/errata/RHSA-2026:65606
CVE-2026-60122

+ RHSA-2026:65117 Important: opentelemetry-collector security update
https://access.redhat.com/errata/RHSA-2026:65117
CVE-2026-33818
CVE-2026-39820
CVE-2026-41178
CVE-2026-42499
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:64824 Important: redis security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:64824
CVE-2026-66373
CVE-2026-81934

+ RHSA-2026:64774 Important: python3.14-cryptography security update
https://access.redhat.com/errata/RHSA-2026:64774
CVE-2026-69248
CVE-2026-69249

+ iOS 26.6.2 and iPadOS 26.6.2 released
https://support.apple.com/en-us/100100

+ Google Chrome 153.0.8010.36/.37 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html

+ FreeBSD 14.5-RELEASE released
https://www.freebsd.org/releases/14.5R/relnotes/

+ Apache Tomcat Native 2.0.16, 1.3.9 released
https://tomcat.apache.org/native-doc/miscellaneous/changelog.html#2.0.16
https://tomcat.apache.org/native-1.3-doc/miscellaneous/changelog.html#1.3.9

+ OpenLDAP-2.7.1, 2.6.15 released
https://www.openldap.org/software/release/changes.html
https://www.openldap.org/software/release/changes_lts.html

+ Postfix stable release 3.11.7 and legacy releases 3.10.14, 3.9.15, 3.8.21, 3.7.23, 3.6.21, 3.5.28 released
https://www.postfix.org/announcements/postfix-3.11.7.html

■Knot DNSの脆弱性情報が公開されました
https://jprs.jp/tech/security/2026-09-08-knotdns.html

VU#718077 UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
https://www.kb.cert.org/vuls/id/718077

VU#859658 Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
https://www.kb.cert.org/vuls/id/859658

VU#943094 ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
https://www.kb.cert.org/vuls/id/943094

ニュース解説
スマホで法人代表者の実印、「商業登記リモート署名」開始 民間と競合も
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12018/?ST=nxt_thmit_security

全日空商事「選べるe-GIFT」で不正交換、管理システムに第三者がアクセス
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900380/?ST=nxt_thmit_security

2026年9月7日月曜日

7日 月曜日、友引

+ Mozilla Firefox 155.0.1 released
https://www.firefox.com/en-US/firefox/155.0.1/releasenotes/

+ Apache Ant 1.10.18 Released
https://ant.apache.org/bindownload.cgi

+ Windows Defender (MsMpEng.exe) Race Condition
https://cxsecurity.com/issue/WLB-2026090007

+ ProFTPD mod_sql post-authentication SQLi RCE
https://cxsecurity.com/issue/WLB-2026090006
CVE-2026-42167

JVN#32505330 エクシングCPTrans-ME-Xにおける複数の脆弱性
https://jvn.jp/jp/JVN32505330/index.html

JVNVU#94249914 CISA ICS Advisory / ICS Medical Advisory(2026年09月03日)
https://jvn.jp/vu/JVNVU94249914/index.html

JVNVU#96680494 Casdoorにおける認可回避の脆弱性
https://jvn.jp/vu/JVNVU96680494/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

2026年9月4日金曜日

4日 金曜日、大安

+ domain-scoped PSL domain cookie
https://curl.se/docs/CVE-2026-82209.html
CVE-2026-82209

+ wolfSSL CA-cache hit overrides callback
https://curl.se/docs/CVE-2026-82208.html
CVE-2026-82208

+ secure cookie attribute bypass with tab
https://curl.se/docs/CVE-2026-80255.html
CVE-2026-80255

+ native CA store conn reuse
https://curl.se/docs/CVE-2026-80231.html
CVE-2026-80231

+ OpenSSL pinning bypass
https://curl.se/docs/CVE-2026-80230.html
CVE-2026-80230

+ OpenSSL provider use-after-free
https://curl.se/docs/CVE-2026-80229.html
CVE-2026-80229

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ HTTP/2 server push UAF
https://curl.se/docs/CVE-2026-18924.html
CVE-2026-18924

+ OpenLDAP SASL authentication bypass
https://curl.se/docs/CVE-2026-13608.html
CVE-2026-13608

+ RHSA-2026:63124 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63124
CVE-2026-33818
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63014 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:63014
CVE-2024-57849
CVE-2025-71132
CVE-2026-45970
CVE-2026-53185
CVE-2026-53391
CVE-2026-53392
CVE-2026-53397
CVE-2026-53399
CVE-2026-63800
CVE-2026-64018
CVE-2026-64268
CVE-2026-64298
CVE-2026-68480
CVE-2026-74581

+ RHSA-2026:63387 Important: Satellite 6.17.11 Async Update
https://access.redhat.com/errata/RHSA-2026:63387
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63386 Important: Satellite 6.18.9 Async Update
https://access.redhat.com/errata/RHSA-2026:63386
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63136 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63136
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63130 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:63130
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ Google Chrome 153.0.8010.27/.28, 152.0.7977.82/.83 relased
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop.html
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html

+ UPDATE: JVNVU#96149019 Apache Tomcatにおける複数の脆弱性(2026年8月25日)
https://jvn.jp/vu/JVNVU96149019/index.html

+ UPDATE: JVNVU#96558110 OpenSSLにおける脆弱性に対するアップデート(2026年8月25日)
https://jvn.jp/vu/JVNVU96558110/index.html

+ UPDATE: JVNVU#92139835 OpenSSLのOCSPレスポンス検証におけるクライアント側のメモリリークの脆弱性(CVE-2026-54876)
https://jvn.jp/vu/JVNVU92139835/index.html

+ UPDATE: JVNVU#99139115 Apache TomcatのWebSocket chatサンプルにおけるサービス運用妨害(DoS)の脆弱性(2026年7月28日)
https://jvn.jp/vu/JVNVU99139115/index.html

+ UPDATE: JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html

+ UPDATE: JVNVU#95286373 Apache Tomcatにおける複数の脆弱性(2026年7月14日)
https://jvn.jp/vu/JVNVU95286373/index.html

VU#889462 Casdoor authentication server is vulnerable to authorization bypass
https://www.kb.cert.org/vuls/id/889462