2026年9月16日水曜日

16日 水曜日、先勝

+ RHSA-2026:67468 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:67468
CVE-2024-53161
CVE-2025-71127
CVE-2026-43133
CVE-2026-52947
CVE-2026-53182
CVE-2026-63802
CVE-2026-63889
CVE-2026-64117
CVE-2026-68363
CVE-2026-72098
CVE-2026-74556

+ RHSA-2026:67315 Moderate: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:67315
CVE-2026-42533

+ RHSA-2026:67278 Moderate: perl:5.32 security update
https://access.redhat.com/errata/RHSA-2026:67278
CVE-2026-13221

+ RHSA-2026:67266 Moderate: libkcapi security update
https://access.redhat.com/errata/RHSA-2026:67266
CVE-2026-71225
CVE-2026-71226
CVE-2026-71227

+ About the security content of iOS 27 and iPadOS 27
https://support.apple.com/en-us/149034
CVE-2026-86882
CVE-2026-43664
CVE-2026-64761
CVE-2026-65404
CVE-2026-84523
CVE-2026-86888
CVE-2026-20683
CVE-2026-65408
CVE-2026-65407
CVE-2026-84519
CVE-2026-84593
CVE-2026-86905
CVE-2026-84583
CVE-2026-65410
CVE-2026-84616
CVE-2026-84607
CVE-2026-65406
CVE-2026-86885
CVE-2026-86879
CVE-2026-65414
CVE-2026-84560
CVE-2026-86878
CVE-2026-86895
CVE-2026-86893
CVE-2026-65399
CVE-2026-64752
CVE-2026-86876
CVE-2026-65344
CVE-2026-84624
CVE-2026-43737
CVE-2026-65412
CVE-2026-84596
CVE-2026-84575
CVE-2026-84489
CVE-2026-84571
CVE-2026-43738
CVE-2026-84511
CVE-2026-84612
CVE-2026-84552
CVE-2026-84510
CVE-2026-43785
CVE-2026-84534
CVE-2026-43688
CVE-2026-84524
CVE-2026-84597
CVE-2026-65409
CVE-2026-84492
CVE-2026-84533
CVE-2026-84606
CVE-2026-64756
CVE-2026-84564
CVE-2026-65395
CVE-2026-28969
CVE-2026-65398
CVE-2026-64760
CVE-2026-65354
CVE-2026-28968
CVE-2026-84566
CVE-2026-65415
CVE-2026-84561
CVE-2026-84630
CVE-2026-65360
CVE-2026-65358
CVE-2026-65377
CVE-2026-84622
CVE-2026-43689
CVE-2026-43687
CVE-2026-43686
CVE-2026-65405
CVE-2026-84530
CVE-2026-84521
CVE-2026-65402
CVE-2026-65359
CVE-2026-84507
CVE-2026-86903
CVE-2026-84602
CVE-2026-86870
CVE-2026-86883
CVE-2026-84628
CVE-2026-86924
CVE-2026-65411
CVE-2026-84598
CVE-2026-84497
CVE-2026-84615
CVE-2026-43695
CVE-2026-84626
CVE-2026-84491
CVE-2026-84629
CVE-2026-84623
CVE-2026-28966
CVE-2026-84532
CVE-2026-65403
CVE-2026-84518
CVE-2026-86897
CVE-2026-84551
CVE-2026-84625
CVE-2026-84603
CVE-2026-84487
CVE-2026-84632
CVE-2026-84620
CVE-2026-84546
CVE-2026-84611
CVE-2026-84526
CVE-2026-86881
CVE-2026-84531
CVE-2026-84600
CVE-2026-86884
CVE-2026-86890
CVE-2026-84609
CVE-2026-84621
CVE-2026-86892
CVE-2026-65348
CVE-2026-65345
CVE-2026-84513
CVE-2026-86886
CVE-2026-84527
CVE-2026-65329
CVE-2026-86887
CVE-2026-86904
CVE-2026-84635
CVE-2026-64753
CVE-2026-86898
CVE-2026-64718
CVE-2026-43674
CVE-2026-84636
CVE-2026-84617

+ About the security content of iOS 26.7 and iPadOS 26.7
https://support.apple.com/en-us/149041

+ About the security content of macOS Golden Gate 27
https://support.apple.com/en-us/149035

+ About the security content of macOS Tahoe 26.7
https://support.apple.com/en-us/149042

+ About the security content of macOS Sequoia 15.8
https://support.apple.com/en-us/149043

+ About the security content of tvOS 27
https://support.apple.com/en-us/149036

+ About the security content of watchOS 27
https://support.apple.com/en-us/149037

+ About the security content of visionOS 27
https://support.apple.com/en-us/149038

+ About the security content of Safari 27
https://support.apple.com/en-us/149039

+ About the security content of Xcode 27
https://support.apple.com/en-us/149040

+ Google Chrome 153.0.8010.47/.48, 152.0.7977.130 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop_01936140552.html

+ Mozill Firefox 156.0 released
https://www.firefox.com/en-US/firefox/156.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-90 Security Vulnerabilities fixed in Firefox 156
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/
CVE-2026-92033
CVE-2026-92005
CVE-2026-92006
CVE-2026-92007
CVE-2026-92008
CVE-2026-92009
CVE-2026-92010
CVE-2026-92011
CVE-2026-92012
CVE-2026-92013
CVE-2026-92015
CVE-2026-92034
CVE-2026-92035
CVE-2026-92016
CVE-2026-92017
CVE-2026-92018
CVE-2026-92019
CVE-2026-92020
CVE-2026-92022
CVE-2026-92023
CVE-2026-92024
CVE-2026-92025
CVE-2026-92026
CVE-2026-92036
CVE-2026-92027
CVE-2026-92028
CVE-2026-92029
CVE-2026-92037
CVE-2026-92038
CVE-2026-92039
CVE-2026-92040
CVE-2026-92041
CVE-2026-92042
CVE-2026-92043
CVE-2026-92044
CVE-2026-92045
CVE-2026-92030
CVE-2026-92046
CVE-2026-92047
CVE-2026-92048
CVE-2026-92049
CVE-2026-92050
CVE-2026-92051
CVE-2026-92052
CVE-2026-92053
CVE-2026-92054
CVE-2026-92055
CVE-2026-92056
CVE-2026-92057
CVE-2026-92031
CVE-2026-92032
CVE-2026-92058
CVE-2026-92059
CVE-2026-92060
CVE-2026-92061
CVE-2026-92062
CVE-2026-92063
CVE-2026-92064
CVE-2026-92065
CVE-2026-92066
CVE-2026-92067
CVE-2026-92068
CVE-2026-92069
CVE-2026-92070
CVE-2026-92071
CVE-2026-92072
CVE-2026-92073
CVE-2026-92074
CVE-2026-92075
CVE-2026-92076
CVE-2026-92077
CVE-2026-92078
CVE-2026-92079

+ Mozilla Foundation Security Advisory 2026-93 Security Vulnerabilities fixed in Firefox ESR 153.3
https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/

+ Mozilla Foundation Security Advisory 2026-92 Security Vulnerabilities fixed in Firefox ESR 140.16
https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/

+ Mozilla Foundation Security Advisory 2026-91 Security Vulnerabilities fixed in Firefox ESR 115.41
https://www.mozilla.org/en-US/security/advisories/mfsa2026-91/

+ Mozilla Thunderbird 156.0 released
https://www.thunderbird.net/en-US/thunderbird/156.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-94 Security Vulnerabilities fixed in Thunderbird 156
https://www.mozilla.org/en-US/security/advisories/mfsa2026-94/

+ Mozilla Foundation Security Advisory 2026-95 Security Vulnerabilities fixed in Thunderbird 140.16
https://www.mozilla.org/en-US/security/advisories/mfsa2026-95/

+ nginx 1.31.6, 1.30.5 released
https://nginx.org/en/CHANGES
https://nginx.org/en/CHANGES-1.30

+ K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439
https://my.f5.com/manage/s/article/K000162604
CVE-2026-90439

+ Apache Tomcat 11.0.26, 10.1.60, 9.0.122 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.26_(markt)
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.60_(schultz)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.122_(remm)

JVN#72918755 Androidアプリ「【保護者専用】まなびポケット」におけるアクセス制限不備の脆弱性
https://jvn.jp/jp/JVN72918755/index.html

JVN#02049764 Lite-On製O-RU「FF-RFI079I4」および「FF-RFI078I4」における複数の脆弱性
https://jvn.jp/jp/JVN02049764/index.html

JVNVU#99837984 パナソニック インダストリー製MINAS A5/A6用Windows USBデバイスドライバにおけるバッファオーバーフローの脆弱性
https://jvn.jp/vu/JVNVU99837984/index.html

JVNVU#99009004 コンテック製無線LAN FLEXLANシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99009004/index.html

JVN#69877538 Androidアプリ「YAMAP / ヤマップ登山地図アプリ」におけるアクセス制限不備の脆弱性
https://jvn.jp/jp/JVN69877538/index.html

JVNVU#94022278 ExLlamaV3のexllamav3_extモジュールにおける不適切な入力検証の脆弱性
https://jvn.jp/vu/JVNVU94022278/index.html

勝村幸博の「今日も誰かが狙われる」
ディープフェイク画像を15分の訓練で見抜く、あなたも挑戦してみよう
https://xtech.nikkei.com/atcl/nxt/column/18/00676/091000233/?ST=nxt_thmit_security

生成AI時代のOSS危機 第3回
OSS保守を襲う「AIスロップ」、変更提案1日200件 サプライチェーン攻撃も
https://xtech.nikkei.com/atcl/nxt/column/18/03754/091100004/?ST=nxt_thmit_security

ニュース解説
Java 27のTLS機能で耐量子暗号が利用可能に、過去のLTS版にも遡って実装
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12033/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
RIZAPで「シャドーAI」、社員が顧客情報を誤投入 委託元が約2万人分被害
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900381/?ST=nxt_thmit_security

生成AI時代のOSS危機 第2回
Anthropic「Mythos」、18時間で8件の攻撃手法を構築 OSS防御は追いつくか
https://xtech.nikkei.com/atcl/nxt/column/18/03754/091000002/?ST=nxt_thmit_security

2026年9月14日月曜日

14日 月曜日、大安

+ ■Windows DNSの脆弱性情報が公開されました(CVE-2026-69730、他17件)
https://jprs.jp/tech/security/2026-09-11-windowsdns.html

VU#369611 ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
https://www.kb.cert.org/vuls/id/369611

JVN#20829034 a-blog cmsにおけるパストラバーサルの脆弱性
https://jvn.jp/jp/JVN20829034/index.html

JVNVU#94404414 CISA ICS Advisory / ICS Medical Advisory(2026年09月10日)
https://jvn.jp/vu/JVNVU94404414/index.html

JVNVU#95258183 AOMEI Backupperのamwrtdrv.sysカーネルドライバにおける権限昇格の脆弱性
https://jvn.jp/vu/JVNVU95258183/index.html

生成AI時代のOSS危機 第1回
提供と利用の双方に「OSSの危機」、AIで増幅 知らないこと自体がリスク
https://xtech.nikkei.com/atcl/nxt/column/18/03754/090900001/?ST=nxt_thmit_security

日経クロステックNEXT 東京 2026特集
AIエージェントによる攻撃出現、VPN以外も標的に ランサム攻撃の最新動向
https://xtech.nikkei.com/atcl/nxt/column/18/03745/090800007/?ST=nxt_thmit_security

国の機関の業務環境GSSに不正侵入、職員の氏名など24万6000件漏洩の恐れ
https://xtech.nikkei.com/atcl/nxt/news/24/03383/?ST=nxt_thmit_security

2026年9月11日金曜日

11日 金曜日、友引

+ RHSA-2026:66348 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:66348
CVE-2026-28420
CVE-2026-52859
CVE-2026-55892
CVE-2026-59857
CVE-2026-73072
CVE-2026-73076
CVE-2026-73078

+ RHSA-2026:66325 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:66325
CVE-2025-68745
CVE-2026-46149
CVE-2026-52917
CVE-2026-52942
CVE-2026-52986
CVE-2026-53091
CVE-2026-53246
CVE-2026-63801
CVE-2026-63971
CVE-2026-64015
CVE-2026-64113
CVE-2026-68117
CVE-2026-68300
CVE-2026-68315
CVE-2026-68376

+ RHSA-2026:66542 Important: nginx security update
https://access.redhat.com/errata/RHSA-2026:66542
CVE-2026-42533

+ RHSA-2026:66403 Moderate: coreutils security update
https://access.redhat.com/errata/RHSA-2026:66403
CVE-2026-56392

+ RHSA-2026:66401 Important: Red Hat OpenStack Platform 17.1 security and bug fix advisory
https://access.redhat.com/errata/RHSA-2026:66401
CVE-2025-61726
CVE-2025-68121
CVE-2026-24708
CVE-2026-25679
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283

+ RHSA-2026:66366 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:66366
CVE-2026-28420
CVE-2026-52859
CVE-2026-55892
CVE-2026-59857
CVE-2026-73072
CVE-2026-73076
CVE-2026-73077
CVE-2026-73078

+ RHSA-2026:66341 Moderate: apr-util security update
https://access.redhat.com/errata/RHSA-2026:66341
CVE-2025-49506
CVE-2026-32327
CVE-2026-34501
CVE-2026-34502

+ 2026 年 9 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/09/202609-security-update

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIエージェント同士が縄張り争い 矛盾した指示によるリスク判明
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/090700194/?ST=nxt_thmit_security

UPDATE: JVNVU#90314828 コンテック製PC-HELPERシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90314828/index.html

JVNVU#96551518 コンテック製CONPROSYSシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96551518/index.html

JVNVU#99009004 コンテック製無線LAN FLEXLANシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99009004/index.html

JVNVU#97753461 コンテック製SolarView Compactにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97753461/index.html

JVN#37476837 SHIRASAGIにおける複数の脆弱性
https://jvn.jp/jp/JVN37476837/index.html

VU#687587 AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
https://www.kb.cert.org/vuls/id/687587