2026年9月14日月曜日

14日 月曜日、大安

+ ■Windows DNSの脆弱性情報が公開されました(CVE-2026-69730、他17件)
https://jprs.jp/tech/security/2026-09-11-windowsdns.html

VU#369611 ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
https://www.kb.cert.org/vuls/id/369611

JVN#20829034 a-blog cmsにおけるパストラバーサルの脆弱性
https://jvn.jp/jp/JVN20829034/index.html

JVNVU#94404414 CISA ICS Advisory / ICS Medical Advisory(2026年09月10日)
https://jvn.jp/vu/JVNVU94404414/index.html

JVNVU#95258183 AOMEI Backupperのamwrtdrv.sysカーネルドライバにおける権限昇格の脆弱性
https://jvn.jp/vu/JVNVU95258183/index.html

生成AI時代のOSS危機 第1回
提供と利用の双方に「OSSの危機」、AIで増幅 知らないこと自体がリスク
https://xtech.nikkei.com/atcl/nxt/column/18/03754/090900001/?ST=nxt_thmit_security

日経クロステックNEXT 東京 2026特集
AIエージェントによる攻撃出現、VPN以外も標的に ランサム攻撃の最新動向
https://xtech.nikkei.com/atcl/nxt/column/18/03745/090800007/?ST=nxt_thmit_security

国の機関の業務環境GSSに不正侵入、職員の氏名など24万6000件漏洩の恐れ
https://xtech.nikkei.com/atcl/nxt/news/24/03383/?ST=nxt_thmit_security

2026年9月11日金曜日

11日 金曜日、友引

+ RHSA-2026:66348 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:66348
CVE-2026-28420
CVE-2026-52859
CVE-2026-55892
CVE-2026-59857
CVE-2026-73072
CVE-2026-73076
CVE-2026-73078

+ RHSA-2026:66325 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:66325
CVE-2025-68745
CVE-2026-46149
CVE-2026-52917
CVE-2026-52942
CVE-2026-52986
CVE-2026-53091
CVE-2026-53246
CVE-2026-63801
CVE-2026-63971
CVE-2026-64015
CVE-2026-64113
CVE-2026-68117
CVE-2026-68300
CVE-2026-68315
CVE-2026-68376

+ RHSA-2026:66542 Important: nginx security update
https://access.redhat.com/errata/RHSA-2026:66542
CVE-2026-42533

+ RHSA-2026:66403 Moderate: coreutils security update
https://access.redhat.com/errata/RHSA-2026:66403
CVE-2026-56392

+ RHSA-2026:66401 Important: Red Hat OpenStack Platform 17.1 security and bug fix advisory
https://access.redhat.com/errata/RHSA-2026:66401
CVE-2025-61726
CVE-2025-68121
CVE-2026-24708
CVE-2026-25679
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283

+ RHSA-2026:66366 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:66366
CVE-2026-28420
CVE-2026-52859
CVE-2026-55892
CVE-2026-59857
CVE-2026-73072
CVE-2026-73076
CVE-2026-73077
CVE-2026-73078

+ RHSA-2026:66341 Moderate: apr-util security update
https://access.redhat.com/errata/RHSA-2026:66341
CVE-2025-49506
CVE-2026-32327
CVE-2026-34501
CVE-2026-34502

+ 2026 年 9 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/09/202609-security-update

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIエージェント同士が縄張り争い 矛盾した指示によるリスク判明
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/090700194/?ST=nxt_thmit_security

UPDATE: JVNVU#90314828 コンテック製PC-HELPERシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90314828/index.html

JVNVU#96551518 コンテック製CONPROSYSシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96551518/index.html

JVNVU#99009004 コンテック製無線LAN FLEXLANシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99009004/index.html

JVNVU#97753461 コンテック製SolarView Compactにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97753461/index.html

JVN#37476837 SHIRASAGIにおける複数の脆弱性
https://jvn.jp/jp/JVN37476837/index.html

VU#687587 AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
https://www.kb.cert.org/vuls/id/687587

2026年9月10日木曜日

10日 木曜日、大安

+ RHSA-2026:66248 Important: ansible-core security update
https://access.redhat.com/errata/RHSA-2026:66248
CVE-2026-11332

+ RHSA-2026:66016 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:66016
CVE-2024-9355
CVE-2024-45336
CVE-2026-33818
CVE-2026-39820
CVE-2026-39821
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:66000 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:66000
CVE-2026-43493
CVE-2026-53002
CVE-2026-64007
CVE-2026-64563
CVE-2026-68343
CVE-2026-72129
CVE-2026-74480

+ RHSA-2026:65998 Moderate: gzip security update
https://access.redhat.com/errata/RHSA-2026:65998
CVE-2026-41991
CVE-2026-41992

+ RHSA-2026:65897 Important: qt5-qtbase security update
https://access.redhat.com/errata/RHSA-2026:65897
CVE-2026-9499

+ RHSA-2026:65832 Important: mrtg security update
https://access.redhat.com/errata/RHSA-2026:65832
CVE-2026-72694

+ RHSA-2026:66204 Important: python-lxml security update
https://access.redhat.com/errata/RHSA-2026:66204
CVE-2026-49825

+ RHSA-2026:66203 Important: python3.12-lxml security update
https://access.redhat.com/errata/RHSA-2026:66203
CVE-2026-49825

+ RHSA-2026:66179 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:66179
CVE-2026-19546

+ RHSA-2026:65993 Important: qt5-qtbase security update
https://access.redhat.com/errata/RHSA-2026:65993
CVE-2026-9499

+ RHSA-2026:65886 Important: image-builder security update
https://access.redhat.com/errata/RHSA-2026:65886
CVE-2026-32280
CVE-2026-32281
CVE-2026-33811
CVE-2026-33818
CVE-2026-39820
CVE-2026-39821
CVE-2026-42499
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ Google Chrome 154.0.8037.17/.18, 152.0.7977.120 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_01157104879.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop.html

+ Mozill Thunderbird 155.0.1 released
https://www.thunderbird.net/en-US/thunderbird/155.0.1/releasenotes/

JVN#21088484 baserCMS用プラグイン「BurgerEditor」における複数の脆弱性
https://jvn.jp/jp/JVN21088484/index.html

JVNVU#93257103 CISA ICS Advisory / ICS Medical Advisory(2026年09月08日)
https://jvn.jp/vu/JVNVU93257103/index.html

JVNVU#94974158 SPI Flashに組み込まれたUEFI Shellモジュールにおけるセキュアブート回避の脆弱性
https://jvn.jp/vu/JVNVU94974158/index.html

JVNVU#94533753 Ascensio System SIA製ONLYOFFICE ownCloud統合プラグインにおけるサーバサイドリクエストフォージェリの脆弱性
https://jvn.jp/vu/JVNVU94533753/index.html

JVNVU#91877671 Skullcandy製ワイヤレスイヤホン「Dime 3」における不適切な認証の脆弱性
https://jvn.jp/vu/JVNVU91877671/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html