+ proto-default skips SSH verification
https://curl.se/docs/CVE-2026-12064.html
CVE-2026-12064
+ cross-origin Digest auth state leak
https://curl.se/docs/CVE-2026-11856.html
CVE-2026-11856
+ WS Auto-PONG memory exhaustion
https://curl.se/docs/CVE-2026-11586.html
CVE-2026-11586
+ Native CA trust persist
https://curl.se/docs/CVE-2026-11564.html
CVE-2026-11564
+ QUIC zero-length UDP datagrams busy-loop
https://curl.se/docs/CVE-2026-11352.html
CVE-2026-11352
+ HTTP/2 stream-dependency tree UAF
https://curl.se/docs/CVE-2026-10536.html
CVE-2026-10536
+ SSH improper host validation
https://curl.se/docs/CVE-2026-9547.html
CVE-2026-9547
+ sending old referer
https://curl.se/docs/CVE-2026-9546.html
CVE-2026-9546
+ exposing HTTP/3 early data
https://curl.se/docs/CVE-2026-9545.html
CVE-2026-9545
+ UAF after pause in socket callback
https://curl.se/docs/CVE-2026-9080.html
CVE-2026-9080
+ stale proxy password leak
https://curl.se/docs/CVE-2026-9079.html
CVE-2026-9079
+ incomplete mTLS config matching in conn reuse
https://curl.se/docs/CVE-2026-8932.html
CVE-2026-8932
+ env-set cross-proxy Digest auth state leak
https://curl.se/docs/CVE-2026-8927.html
CVE-2026-8927
+ password leak with netrc and user in URL
https://curl.se/docs/CVE-2026-8926.html
CVE-2026-8926
+ SASL double-free
https://curl.se/docs/CVE-2026-8925.html
CVE-2026-8925
+ trailing dot domain super cookie
https://curl.se/docs/CVE-2026-8924.html
CVE-2026-8924
+ wrong reuse for different services
https://curl.se/docs/CVE-2026-8458.html
CVE-2026-8458
+ wrong STARTTLS connection reuse
https://curl.se/docs/CVE-2026-8286.html
CVE-2026-8286
+ RHSA-2026:28998 Important: evince security update
https://access.redhat.com/errata/RHSA-2026:28998
CVE-2026-46529
+ RHSA-2026:28923 Important: tigervnc security update
https://access.redhat.com/errata/RHSA-2026:28923
CVE-2026-50256
CVE-2026-50257
CVE-2026-50258
CVE-2026-50259
CVE-2026-50260
CVE-2026-50261
CVE-2026-50262
CVE-2026-50263
CVE-2026-50264
+ RHSA-2026:28922 Moderate: libreoffice security update
https://access.redhat.com/errata/RHSA-2026:28922
CVE-2026-4430
+ RHSA-2026:28921 Important: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:28921
CVE-2026-9256
+ RHSA-2026:29151 Important: nginx:1.26 security update
https://access.redhat.com/errata/RHSA-2026:29151
CVE-2026-9256
+ RHSA-2026:28973 Important: nginx security update
https://access.redhat.com/errata/RHSA-2026:28973
CVE-2026-9256
+ RHSA-2026:28911 Moderate: coreutils security update
https://access.redhat.com/errata/RHSA-2026:28911
CVE-2025-5278
+ RHSA-2026:28741 Critical: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:28741
CVE-2026-43037
+ Google Chrome 150.0.7871.46/.47 released
https://chromereleases.googleblog.com/2026/06/early-stable-update-for-desktop_01696591429.html
JVNVU#98428308 CISA ICS Advisory / ICS Medical Advisory(2026年06月23日)
https://jvn.jp/vu/JVNVU98428308/index.html
ニュース&リポート
日立がMythosのアクセス権獲得 社会インフラの安全性向上に一手
米アンソロピックは次世代モデルの提供を停止
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/061801453/?ST=nxt_thmit_security
piyokangoの月刊システムトラブル
YCC情報システムが第5報 管理者アカウントを使われたか
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/061700088/?ST=nxt_thmit_security
基礎から理解する暗号 第3回
送信者の身元をどう保証する? 公開鍵暗号を応用する「電子署名」を知る
https://xtech.nikkei.com/atcl/nxt/column/18/03656/061900003/?ST=nxt_thmit_security
ニュース解説
KDDIのメール「OEM」サービスで情報漏洩疑い、ISP各社が外注する事情
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11845/?ST=nxt_thmit_security