2026年9月4日金曜日

4日 金曜日、大安

+ domain-scoped PSL domain cookie
https://curl.se/docs/CVE-2026-82209.html
CVE-2026-82209

+ wolfSSL CA-cache hit overrides callback
https://curl.se/docs/CVE-2026-82208.html
CVE-2026-82208

+ secure cookie attribute bypass with tab
https://curl.se/docs/CVE-2026-80255.html
CVE-2026-80255

+ native CA store conn reuse
https://curl.se/docs/CVE-2026-80231.html
CVE-2026-80231

+ OpenSSL pinning bypass
https://curl.se/docs/CVE-2026-80230.html
CVE-2026-80230

+ OpenSSL provider use-after-free
https://curl.se/docs/CVE-2026-80229.html
CVE-2026-80229

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ HTTP/2 server push UAF
https://curl.se/docs/CVE-2026-18924.html
CVE-2026-18924

+ OpenLDAP SASL authentication bypass
https://curl.se/docs/CVE-2026-13608.html
CVE-2026-13608

+ RHSA-2026:63124 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63124
CVE-2026-33818
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63014 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:63014
CVE-2024-57849
CVE-2025-71132
CVE-2026-45970
CVE-2026-53185
CVE-2026-53391
CVE-2026-53392
CVE-2026-53397
CVE-2026-53399
CVE-2026-63800
CVE-2026-64018
CVE-2026-64268
CVE-2026-64298
CVE-2026-68480
CVE-2026-74581

+ RHSA-2026:63387 Important: Satellite 6.17.11 Async Update
https://access.redhat.com/errata/RHSA-2026:63387
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63386 Important: Satellite 6.18.9 Async Update
https://access.redhat.com/errata/RHSA-2026:63386
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63136 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63136
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63130 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:63130
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ Google Chrome 153.0.8010.27/.28, 152.0.7977.82/.83 relased
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop.html
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html

+ UPDATE: JVNVU#96149019 Apache Tomcatにおける複数の脆弱性(2026年8月25日)
https://jvn.jp/vu/JVNVU96149019/index.html

+ UPDATE: JVNVU#96558110 OpenSSLにおける脆弱性に対するアップデート(2026年8月25日)
https://jvn.jp/vu/JVNVU96558110/index.html

+ UPDATE: JVNVU#92139835 OpenSSLのOCSPレスポンス検証におけるクライアント側のメモリリークの脆弱性(CVE-2026-54876)
https://jvn.jp/vu/JVNVU92139835/index.html

+ UPDATE: JVNVU#99139115 Apache TomcatのWebSocket chatサンプルにおけるサービス運用妨害(DoS)の脆弱性(2026年7月28日)
https://jvn.jp/vu/JVNVU99139115/index.html

+ UPDATE: JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html

+ UPDATE: JVNVU#95286373 Apache Tomcatにおける複数の脆弱性(2026年7月14日)
https://jvn.jp/vu/JVNVU95286373/index.html

VU#889462 Casdoor authentication server is vulnerable to authorization bypass
https://www.kb.cert.org/vuls/id/889462

2026年9月3日木曜日

3日 木曜日、仏滅

+ RHSA-2026:62667 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:62667
CVE-2026-9698
CVE-2026-10879
CVE-2026-14380
CVE-2026-14739

+ RHSA-2026:62583 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:62583
CVE-2026-56846
CVE-2026-56848
CVE-2026-58043

+ RHSA-2026:62571 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:62571
CVE-2026-55194
CVE-2026-67288
CVE-2026-67291
CVE-2026-67301

+ RHSA-2026:62507 Important: gimp:2.8 security update
https://access.redhat.com/errata/RHSA-2026:62507
CVE-2026-18301
CVE-2026-18303
CVE-2026-18304
CVE-2026-18305
CVE-2026-18306
CVE-2026-18307
CVE-2026-58380
CVE-2026-66758

+ RHSA-2026:62425 Important: gegl security update
https://access.redhat.com/errata/RHSA-2026:62425
CVE-2026-18300

+ RHSA-2026:62420 Important: gegl04 security update
https://access.redhat.com/errata/RHSA-2026:62420
CVE-2026-18300

+ RHSA-2026:62407 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:62407
CVE-2026-33818
CVE-2026-39820
CVE-2026-42499
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:62334 Important: php:7.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:62334
CVE-2026-7260
CVE-2026-17543

+ RHSA-2026:62144 Moderate: wget security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:62144
CVE-2026-58469
CVE-2026-58471
CVE-2026-58472

+ RHSA-2026:62640 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:62640
CVE-2026-43112
CVE-2026-43114
CVE-2026-46323
CVE-2026-52973
CVE-2026-53264

+ RHSA-2026:62217 Moderate: libssh security update
https://access.redhat.com/errata/RHSA-2026:62217
CVE-2026-59843
CVE-2026-59844
CVE-2026-59845
CVE-2026-59846
CVE-2026-59847
CVE-2026-59848
CVE-2026-59850

+ RHSA-2026:61903 Important: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:61903
CVE-2026-7260
CVE-2026-17543

+ nginx 1.31.5 released
https://nginx.org/en/CHANGES

+ Mozilla Thunderbrid 155.0 released
https://www.thunderbird.net/en-US/thunderbird/155.0/releasenotes/

ニュース&リポート
オープンAIが先端AIの安全対策緩和 中国モデルの台頭に危機感
サイバー防御プログラム拡充、一部の個人・組織に提供
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/082701491/?ST=nxt_thmit_security

NECがAnthropicの「Mythos」利用権、社内の脆弱性管理に活用
https://xtech.nikkei.com/atcl/nxt/news/24/03370/?ST=nxt_thmit_security

JVNVU#98062224 キーエンス製XG VisionTerminalおよびXG-X VisionTerminalにおけるにおけるXML外部エンティティ参照(XXE)の不適切な制限の脆弱性
https://jvn.jp/vu/JVNVU98062224/index.html

JVN#91715694 ShizenBox2における複数の脆弱性
https://jvn.jp/jp/JVN91715694/index.html

JVNVU#97909245 Hugging Face製Transformersにおけるユーザー同意確認前のリモートコード不正キャッシュの脆弱性
https://jvn.jp/vu/JVNVU97909245/index.html

JVNVU#90253159 CISA ICS Advisory / ICS Medical Advisory(2026年09月01日)
https://jvn.jp/vu/JVNVU90253159/index.html

2026年9月2日水曜日

2日 火曜日、先負

+ Google Chrome 152.0.7977.75/.76 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html

+ Mozilla Firefox 155.0 released
https://www.firefox.com/en-US/firefox/155.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-82 Security Vulnerabilities fixed in Firefox 155
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/
CVE-2026-84117
CVE-2026-84118
CVE-2026-84119
CVE-2026-84120
CVE-2026-84121
CVE-2026-84122
CVE-2026-84123
CVE-2026-84124
CVE-2026-84125
CVE-2026-84126
CVE-2026-84127
CVE-2026-84128
CVE-2026-84129
CVE-2026-84130
CVE-2026-84131
CVE-2026-84132
CVE-2026-84133
CVE-2026-84134
CVE-2026-84135
CVE-2026-84136
CVE-2026-84137
CVE-2026-84138
CVE-2026-84139
CVE-2026-84140
CVE-2026-84141
CVE-2026-84142
CVE-2026-84143
CVE-2026-84144
CVE-2026-84145

+ Mozilla Foundation Security Advisory 2026-85 Security Vulnerabilities fixed in Firefox ESR 153.2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/

+ Mozilla Foundation Security Advisory 2026-84 Security Vulnerabilities fixed in Firefox ESR 140.15
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/

+ Mozilla Foundation Security Advisory 2026-83 Security Vulnerabilities fixed in Firefox ESR 115.40
https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/

+ Mozilla Foundation Security Advisory 2026-88 Security Vulnerabilities fixed in Thunderbird 153.2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/

+ Mozilla Foundation Security Advisory 2026-87 Security Vulnerabilities fixed in Thunderbird 140.15
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/

+ Mozilla Foundation Security Advisory 2026-86 Security Vulnerabilities fixed in Thunderbird 155
https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/

VU#456290 Hugging Face Transformers library writes remote code to disk prior to consent check
https://www.kb.cert.org/vuls/id/456290

決算が暴くサイバー被害
被害企業の防止策 守りより「復旧力」へ [Part 4]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700004/?ST=nxt_thmit_security

決算が暴くサイバー被害
ランサム損失は28社 1年で倍の236億円に [Part 3]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700003/?ST=nxt_thmit_security

決算が暴くサイバー被害
18社が損失計上 海外拠点が標的に [Part 2]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700002/?ST=nxt_thmit_security

マルウエア徹底解剖
AIを取り巻くサイバー脅威を整理する [第81回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/081800082/?ST=nxt_thmit_security

データは語る
67%がSCS評価制度の取り組み進行 業務システムの共同利用は約9割
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/082700232/?ST=nxt_thmit_security

決算が暴くサイバー被害
「社長の声」装い詐取 不正アクセスなき詐欺 [Part 1]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700001/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIエージェント同士が「縄張り争い」、矛盾した指示によるリスク明らかに
https://xtech.nikkei.com/atcl/nxt/column/18/00676/082500232/?ST=nxt_thmit_security