2026年9月25日金曜日

25日 金曜日、仏滅

+ Gpg4win 5.1.1 released
https://www.gpg4win.org/change-history.html

+ RHSA-2026:71652 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:71652
CVE-2026-92005
CVE-2026-92006
CVE-2026-92007
CVE-2026-92008
CVE-2026-92009
CVE-2026-92010
CVE-2026-92011
CVE-2026-92012
CVE-2026-92013
CVE-2026-92014
CVE-2026-92015
CVE-2026-92016
CVE-2026-92017
CVE-2026-92018
CVE-2026-92019
CVE-2026-92020
CVE-2026-92021
CVE-2026-92022
CVE-2026-92023
CVE-2026-92024
CVE-2026-92025
CVE-2026-92026
CVE-2026-92027
CVE-2026-92028
CVE-2026-92029
CVE-2026-92030
CVE-2026-92031
CVE-2026-92032

+ RHSA-2026:71641 Important: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:71641
CVE-2026-74860
CVE-2026-86138
CVE-2026-86140
CVE-2026-86143
CVE-2026-86144

+ RHSA-2026:71608 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:71608
CVE-2026-73194

+ RHSA-2026:71213 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:71213
CVE-2026-43370
CVE-2026-63831
CVE-2026-64564
CVE-2026-72261
CVE-2026-80844
CVE-2026-81000
CVE-2026-89846

+ RHSA-2026:70754 Critical: unbound security update
https://access.redhat.com/errata/RHSA-2026:70754
CVE-2026-81634
CVE-2026-81642
CVE-2026-82717

+ RHSA-2026:70630 Moderate: java-1.8.0-ibm security update
https://access.redhat.com/errata/RHSA-2026:70630
CVE-2026-16440
CVE-2026-60589
CVE-2026-61308
CVE-2026-70907

+ RHSA-2026:70402 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:70402
CVE-2023-54120
CVE-2023-54214
CVE-2025-39964
CVE-2025-71082
CVE-2026-43334
CVE-2026-45894
CVE-2026-46043
CVE-2026-46133
CVE-2026-52918
CVE-2026-53053
CVE-2026-53062
CVE-2026-53254
CVE-2026-53256
CVE-2026-63823
CVE-2026-63947
CVE-2026-63975
CVE-2026-64534
CVE-2026-64582
CVE-2026-68188
CVE-2026-68293

+ RHSA-2026:70390 Moderate: tar security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:70390
CVE-2025-45582
CVE-2026-5704
CVE-2026-18477
CVE-2026-18508

+ RHSA-2026:69964 Moderate: coreutils security update
https://access.redhat.com/errata/RHSA-2026:69964
CVE-2025-5278

+ watchOS 27.0.1 released
https://support.apple.com/en-us/100100

+ Google Chrome 155.0.8059.12/.13 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_01050350268.html

+ Mozilla Firefox 156.0.1 released
https://www.firefox.com/en-US/firefox/156.0.1/releasenotes/

+ Zabbix 7.4.15, 7.0.31 released
https://www.zabbix.com/rn/rn7.4.15
https://www.zabbix.com/rn/rn7.0.31

+ Mozilla Thunderbird 156.0.1 released
https://www.thunderbird.net/en-US/thunderbird/156.0.1/releasenotes/

+ Wireshark 4.6.9, 4,4,19 released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.9.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.19.html

+ PHP 8.5.11, 8.4.26, 8.3.35, 8.2.34 released
https://www.php.net/ChangeLog-8.php#8.5.11
https://www.php.net/ChangeLog-8.php#8.4.26
https://www.php.net/ChangeLog-8.php#8.3.35
https://www.php.net/ChangeLog-8.php#8.2.34

+ Apache Tomcatの脆弱性(Critical: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, High: CVE-2026-75973, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-87022, Medium: CVE-2026-73581, Low: CVE-2026-77756)
https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260924/
CVE-2026-76183
CVE-2026-86248
CVE-2026-86350
CVE-2026-75973
CVE-2026-77762
CVE-2026-77791
CVE-2026-78383
CVE-2026-78437
CVE-2026-79677
CVE-2026-87022
CVE-2026-73581
CVE-2026-77756

VU#234131 ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
https://www.kb.cert.org/vuls/id/234131

VU#676317 Norwegian Cruise Line door access controller contains an improper authentication vulnerability
https://www.kb.cert.org/vuls/id/676317

VU#273940 Enterprise Access Management EAM does not rotate RSA keys
https://www.kb.cert.org/vuls/id/273940

VU#754548
Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi?user chat handlers
https://www.kb.cert.org/vuls/id/754548

VU#738147 Vendor-signed UEFI Shell applications allow Secure Boot bypass
https://www.kb.cert.org/vuls/id/738147

piyokangoの月刊システムトラブル
全日空商事でギフト不正交換 原因は第三者の不正アクセス
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/091400091/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
ディープフェイクを訓練で見抜く 整い過ぎた顔や高画質がヒント
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/091700195/?ST=nxt_thmit_security

日経コンピュータ 中田敦のGAFA深読み
メタの新AIエージェント「Muse」 機密コンピューティングに注目
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100111/092400186/?ST=nxt_thmit_security

JVN#21754394 baserCMS用プラグイン「アドオンマイグレーター」 における信頼できない制御領域からの機能の組み込みに関する脆弱性
https://jvn.jp/jp/JVN21754394/index.html

JVN#14353754 baserCMSにおける複数の脆弱性
https://jvn.jp/jp/JVN14353754/index.html

JVNVU#96941087 ViewSonic vCastにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96941087/index.html

JVNVU#96565230 Norwegian Cruise Lineのドアアクセスコントローラにおける認証不備の脆弱性
https://jvn.jp/vu/JVNVU96565230/index.html

JVNVU#93222287 CISA ICS Advisory / ICS Medical Advisory(2026年09月24日)
https://jvn.jp/vu/JVNVU93222287/index.html

0 件のコメント:

コメントを投稿