2026年10月5日月曜日

5日 月曜日、友引

+ Google Chrome 152.0.7977.152 released
https://chromereleases.googleblog.com/2026/10/extended-stable-update-for-desktop.html

+ Apache Struts 7.4.0, 6.12.0 released
https://cwiki.apache.org/confluence/spaces/WW/pages/451974607/Version+Notes+7.4.0
https://cwiki.apache.org/confluence/spaces/WW/pages/451974606/Version+Notes+6.12.0

+ libpng 1.6.59 released
https://www.libpng.org/pub/png/src/libpng-1.6.59-README.txt

+ JVNVU#94648869 Apache HTTP Server 2.4における複数の脆弱性に対するアップデート(2026年10月1日)
https://jvn.jp/vu/JVNVU94648869/index.html

+ Apache HTTP Serverの脆弱性(Moderate: CVE-2026-42528, CVE-2026-57941, CVE-2026-59685, CVE-2026-63292, CVE-2026-93546, Low: 複数)と新バージョン(2.4.69)
https://security.sios.jp/vulnerability/apache-security-vulnerability-20261002/
CVE-2026-42528
CVE-2026-57941
CVE-2026-59685
CVE-2026-63292
CVE-2026-93546
CVE-2026-42356
CVE-2026-46729
CVE-2026-47360
CVE-2026-48005
CVE-2026-56153
CVE-2026-56154
CVE-2026-56449
CVE-2026-58415
CVE-2026-59797
CVE-2026-63045
CVE-2026-63686
CVE-2026-63718
CVE-2026-73636
CVE-2026-73637
CVE-2026-79768

マルウエア徹底解剖
マルウエア解析ツール徹底解説・前編 [第82回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/091400083/?ST=nxt_thmit_security

タイムズカー、退会者にも漏洩状況を個別通知 確認から案内まで約2週間
https://xtech.nikkei.com/atcl/nxt/news/24/03404/?ST=nxt_thmit_security

JVNVU#91842649 CISA ICS Advisory / ICS Medical Advisory(2026年10月01日)
https://jvn.jp/vu/JVNVU91842649/index.html

JVNVU#92911062 InsydeH2O IHISIにおける安全でないメモリ書き込みの脆弱性
https://jvn.jp/vu/JVNVU92911062/index.html

2026年10月2日金曜日

2日 金曜日、大安

+ Mozilla Thunderbrird 157.0.1 released
https://www.thunderbird.net/en-US/thunderbird/157.0.1/releasenotes/

+ Apache HTTP Server 2.4.69 released
https://downloads.apache.org/httpd/Announcement2.4.html
https://downloads.apache.org/httpd/CHANGES_2.4.69

+ JVNVU#93468181 OpenSSLにおける脆弱性に対するアップデート(2026年9月29日)
https://jvn.jp/vu/JVNVU93468181/index.html

VU#553437 InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations
https://www.kb.cert.org/vuls/id/553437

絵で見て分かるネットワーク必修キーワード
送信ドメイン認証
メールの送信元が正しいか確認する技術
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091900172/091400037/?ST=nxt_thmit_security

2026年10月1日木曜日

1日 木曜日、仏滅

+ RHSA-2026:74133 Moderate: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:74133
CVE-2026-64102
CVE-2026-68299
CVE-2026-72099
CVE-2026-72329

+ RHSA-2026:74095 Important: rsync security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:74095
CVE-2026-53783
CVE-2026-53784
CVE-2026-53785
CVE-2026-53789
CVE-2026-53790
CVE-2026-53793
CVE-2026-53795
CVE-2026-53802
CVE-2026-53803
CVE-2026-70452
CVE-2026-70453
CVE-2026-70456
CVE-2026-70458
CVE-2026-70460
CVE-2026-70461
CVE-2026-70463
CVE-2026-70464

+ RHSA-2026:74084 Critical: webkit2gtk3 security update
https://access.redhat.com/errata/RHSA-2026:74084
CVE-2023-4860
CVE-2024-7532
CVE-2024-7966
CVE-2024-8193
CVE-2024-8198
CVE-2024-8636
CVE-2024-9123
CVE-2025-0436
CVE-2025-0444
CVE-2025-8901
CVE-2025-9478
CVE-2025-10502
CVE-2026-0908
CVE-2026-3536
CVE-2026-3538
CVE-2026-3909
CVE-2026-3931
CVE-2026-4448
CVE-2026-4452
CVE-2026-4460
CVE-2026-4464
CVE-2026-5275
CVE-2026-5277
CVE-2026-5283
CVE-2026-5868
CVE-2026-5870
CVE-2026-5879
CVE-2026-6296
CVE-2026-6298
CVE-2026-6364
CVE-2026-7340
CVE-2026-7353
CVE-2026-7354
CVE-2026-7359
CVE-2026-7900
CVE-2026-7901
CVE-2026-7903
CVE-2026-7920
CVE-2026-7923
CVE-2026-7942
CVE-2026-7943
CVE-2026-7949
CVE-2026-8510
CVE-2026-8519
CVE-2026-8525
CVE-2026-8554
CVE-2026-8556
CVE-2026-8567
CVE-2026-8579
CVE-2026-9877
CVE-2026-9878
CVE-2026-9879
CVE-2026-9882
CVE-2026-9892
CVE-2026-9893
CVE-2026-9899
CVE-2026-9900
CVE-2026-9901
CVE-2026-9904
CVE-2026-9908
CVE-2026-9909
CVE-2026-9910
CVE-2026-9911
CVE-2026-9913
CVE-2026-9914
CVE-2026-9915
CVE-2026-9916
CVE-2026-9923
CVE-2026-9924
CVE-2026-9925
CVE-2026-9926
CVE-2026-9927
CVE-2026-9928
CVE-2026-9932
CVE-2026-9935
CVE-2026-9940
CVE-2026-9941
CVE-2026-9942
CVE-2026-9944
CVE-2026-9946
CVE-2026-9953
CVE-2026-9965
CVE-2026-9969
CVE-2026-9975
CVE-2026-9981
CVE-2026-9982
CVE-2026-9983
CVE-2026-9998
CVE-2026-9999
CVE-2026-10009
CVE-2026-10011
CVE-2026-10012
CVE-2026-10018
CVE-2026-10019
CVE-2026-10020
CVE-2026-10881
CVE-2026-10883
CVE-2026-10889
CVE-2026-10907
CVE-2026-10913
CVE-2026-10914
CVE-2026-10919
CVE-2026-10925
CVE-2026-10929
CVE-2026-10930
CVE-2026-10941
CVE-2026-10955
CVE-2026-10974
CVE-2026-10977
CVE-2026-10979
CVE-2026-10985
CVE-2026-10993
CVE-2026-10994
CVE-2026-10999
CVE-2026-11004
CVE-2026-11005
CVE-2026-11024
CVE-2026-11039
CVE-2026-11040
CVE-2026-11043
CVE-2026-11044
CVE-2026-11051
CVE-2026-11055
CVE-2026-11057
CVE-2026-11061
CVE-2026-11065
CVE-2026-11066
CVE-2026-11087
CVE-2026-11088
CVE-2026-11090
CVE-2026-11099
CVE-2026-11104
CVE-2026-11109
CVE-2026-11110
CVE-2026-11111
CVE-2026-11113
CVE-2026-11121
CVE-2026-11123
CVE-2026-11124
CVE-2026-11137
CVE-2026-11138
CVE-2026-11159
CVE-2026-11191
CVE-2026-11268
CVE-2026-11663
CVE-2026-11675
CVE-2026-13780
CVE-2026-13781
CVE-2026-13819
CVE-2026-13820
CVE-2026-13833
CVE-2026-13834
CVE-2026-13841
CVE-2026-13859
CVE-2026-13877
CVE-2026-13883
CVE-2026-13885
CVE-2026-13971
CVE-2026-13975
CVE-2026-14044
CVE-2026-14125
CVE-2026-14152
CVE-2026-14382
CVE-2026-14384
CVE-2026-14385
CVE-2026-14386
CVE-2026-14387
CVE-2026-14388
CVE-2026-14389
CVE-2026-14390
CVE-2026-14391
CVE-2026-14396
CVE-2026-14397
CVE-2026-14398
CVE-2026-14400
CVE-2026-14401
CVE-2026-14402
CVE-2026-14410
CVE-2026-14411
CVE-2026-14412
CVE-2026-14413
CVE-2026-14414
CVE-2026-14418
CVE-2026-14419
CVE-2026-14425
CVE-2026-14427
CVE-2026-14429
CVE-2026-15109
CVE-2026-15766
CVE-2026-15774
CVE-2026-16413
CVE-2026-16417
CVE-2026-16419
CVE-2026-17653
CVE-2026-17655
CVE-2026-17667
CVE-2026-17668
CVE-2026-17671
CVE-2026-17675
CVE-2026-17676
CVE-2026-17677
CVE-2026-17678
CVE-2026-17682
CVE-2026-17683
CVE-2026-17687
CVE-2026-17689
CVE-2026-17691
CVE-2026-17695
CVE-2026-17697
CVE-2026-17701
CVE-2026-17702
CVE-2026-17704
CVE-2026-17712
CVE-2026-17714
CVE-2026-17717
CVE-2026-17718
CVE-2026-17721
CVE-2026-17740
CVE-2026-17745
CVE-2026-17750
CVE-2026-17757
CVE-2026-17771
CVE-2026-17785
CVE-2026-17790
CVE-2026-17801
CVE-2026-17811
CVE-2026-17832
CVE-2026-17847
CVE-2026-17891
CVE-2026-17914
CVE-2026-19154
CVE-2026-19157
CVE-2026-19160
CVE-2026-19161
CVE-2026-19173
CVE-2026-19176
CVE-2026-28984
CVE-2026-39872
CVE-2026-43663
CVE-2026-43676
CVE-2026-43699
CVE-2026-43701
CVE-2026-43707
CVE-2026-43712
CVE-2026-43713
CVE-2026-43715
CVE-2026-43716
CVE-2026-43720
CVE-2026-43721
CVE-2026-43725
CVE-2026-43726
CVE-2026-43727
CVE-2026-43731
CVE-2026-43732
CVE-2026-43734
CVE-2026-43740
CVE-2026-43742
CVE-2026-43745
CVE-2026-43795
CVE-2026-43804
CVE-2026-64713
CVE-2026-64715
CVE-2026-64718
CVE-2026-64728
CVE-2026-64730
CVE-2026-64753
CVE-2026-64757
CVE-2026-64778
CVE-2026-64779
CVE-2026-64780
CVE-2026-64782
CVE-2026-64783
CVE-2026-64784
CVE-2026-64787
CVE-2026-65331
CVE-2026-65332
CVE-2026-65333
CVE-2026-65334
CVE-2026-65335
CVE-2026-65336
CVE-2026-65337
CVE-2026-65338
CVE-2026-65340
CVE-2026-65341
CVE-2026-65351
CVE-2026-76041
CVE-2026-76046
CVE-2026-78376
CVE-2026-78904
CVE-2026-78905
CVE-2026-78906
CVE-2026-78914
CVE-2026-78958
CVE-2026-78965
CVE-2026-78978
CVE-2026-78989
CVE-2026-79019
CVE-2026-79020
CVE-2026-79043
CVE-2026-79048
CVE-2026-79112
CVE-2026-79118
CVE-2026-79120
CVE-2026-79127
CVE-2026-79130
CVE-2026-79131
CVE-2026-79138
CVE-2026-79142
CVE-2026-79144
CVE-2026-79147
CVE-2026-79149
CVE-2026-79188
CVE-2026-79189
CVE-2026-79229
CVE-2026-79230
CVE-2026-79240
CVE-2026-79269
CVE-2026-79270
CVE-2026-79275
CVE-2026-79282
CVE-2026-79285
CVE-2026-83596
CVE-2026-84635

+ RHSA-2026:73971 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:73971
CVE-2026-16365
CVE-2026-75874
CVE-2026-84119
CVE-2026-84120
CVE-2026-84121
CVE-2026-84122
CVE-2026-84124
CVE-2026-84131
CVE-2026-84143
CVE-2026-84145
CVE-2026-84639
CVE-2026-84640
CVE-2026-84641
CVE-2026-92005
CVE-2026-92006
CVE-2026-92007
CVE-2026-92008
CVE-2026-92009
CVE-2026-92010
CVE-2026-92011
CVE-2026-92012
CVE-2026-92013
CVE-2026-92014
CVE-2026-92015
CVE-2026-92016
CVE-2026-92017
CVE-2026-92018
CVE-2026-92019
CVE-2026-92020
CVE-2026-92021
CVE-2026-92022
CVE-2026-92023
CVE-2026-92024
CVE-2026-92025
CVE-2026-92026
CVE-2026-92027
CVE-2026-92028
CVE-2026-92029
CVE-2026-92030
CVE-2026-92031
CVE-2026-92032
CVE-2026-92238
CVE-2026-92239
CVE-2026-92240

+ RHSA-2026:73915 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:73915
CVE-2026-84445

+ RHSA-2026:73519 Important: ruby:2.5 security update
https://access.redhat.com/errata/RHSA-2026:73519
CVE-2026-80212
CVE-2026-88030

+ Google Chrome 155.0.8059.26/.27 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_01356833751.html

+ Mozilla Foundation Security Advisory 2026-101 Security Vulnerabilities fixed in Thunderbird 157
https://www.mozilla.org/en-US/security/advisories/mfsa2026-101/
CVE-2026-103500
CVE-2026-100756
CVE-2026-100757
CVE-2026-100758
CVE-2026-100759
CVE-2026-100760
CVE-2026-100761
CVE-2026-100762
CVE-2026-100763
CVE-2026-100764
CVE-2026-100765
CVE-2026-100766
CVE-2026-100767
CVE-2026-100768
CVE-2026-100769
CVE-2026-100770
CVE-2026-100771
CVE-2026-100772
CVE-2026-100773
CVE-2026-100774
CVE-2026-100775
CVE-2026-100776
CVE-2026-100777
CVE-2026-100778
CVE-2026-100779
CVE-2026-100780
CVE-2026-100781
CVE-2026-100782
CVE-2026-100783
CVE-2026-100784
CVE-2026-100785
CVE-2026-100786
CVE-2026-100787
CVE-2026-100788
CVE-2026-100789
CVE-2026-100790
CVE-2026-100791
CVE-2026-100792
CVE-2026-100793
CVE-2026-100794
CVE-2026-96869
CVE-2026-100795
CVE-2026-100796
CVE-2026-100797
CVE-2026-100798
CVE-2026-100799
CVE-2026-100800
CVE-2026-100801
CVE-2026-100802
CVE-2026-100803
CVE-2026-100804
CVE-2026-100805
CVE-2026-100806
CVE-2026-100807
CVE-2026-100808
CVE-2026-100809
CVE-2026-100810
CVE-2026-100811
CVE-2026-100812
CVE-2026-100813
CVE-2026-100814
CVE-2026-100815
CVE-2026-100816
CVE-2026-100817
CVE-2026-100818
CVE-2026-100819
CVE-2026-100820
CVE-2026-100821
CVE-2026-100822
CVE-2026-100824
CVE-2026-100825
CVE-2026-100826
CVE-2026-100828
CVE-2026-100829
CVE-2026-100830
CVE-2026-100831

+ Mozilla Foundation Security Advisory 2026-103 Security Vulnerabilities fixed in Thunderbird 153.4
https://www.mozilla.org/en-US/security/advisories/mfsa2026-103/

+ Mozilla Foundation Security Advisory 2026-102 Security Vulnerabilities fixed in Thunderbird 140.17
https://www.mozilla.org/en-US/security/advisories/mfsa2026-102/

+ Mozilla Thunderbird 157.0 released
https://www.thunderbird.net/en-US/thunderbird/157.0/releasenotes/

+ OpenSSLの脆弱性(High: CVE-2026-84782, Moderate: CVE-2026-84783, Low: CVE-2026-35189, CVE-2026-35191, CVE-2026-42772, CVE-2026-54872, CVE-2026-54873, CVE-2026-54875, CVE-2026-72897, CVE-2026-75804, CVE-2026-75805, CVE-2026-75806, CVE-2026-77696, CVE-2026-84784)と4.0.3, 3.6.5, 3.5.9, 3.4.8, 3.0.23, 1.1.1zj, 1.0.2zsリリース
https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260930/
CVE-2026-84782
CVE-2026-84783
CVE-2026-35189
CVE-2026-35191
CVE-2026-42772
CVE-2026-54872
CVE-2026-54873
CVE-2026-54875
CVE-2026-72897
CVE-2026-75804
CVE-2026-75805
CVE-2026-75806
CVE-2026-77696
CVE-2026-84784

月刊ランサムリポート
急増する「DeadLock」による被害 感染後すぐに1対1のチャットに誘導
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/091400020/?ST=nxt_thmit_security

吉川孝志のマルウエア徹底解剖 第32回
マルウエア解析は表層・動的・静的の3段階で進む、解析対象とツールを解説
https://xtech.nikkei.com/atcl/nxt/column/18/02805/091500033/?ST=nxt_thmit_security

ニュース解説
Lattice、ポスト量子暗号対応のFPGA AIエージェントで設計支援
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12057/?ST=nxt_thmit_security

「タイムズカー」不正アクセス、免許証画像など約160万件が漏洩
https://xtech.nikkei.com/atcl/nxt/news/24/03401/?ST=nxt_thmit_security

JVNVU#90160989 富士フイルムビジネスイノベーション製およびシャープ製複合機(MFP)におけるパストラバーサルの脆弱性
https://jvn.jp/vu/JVNVU90160989/index.html

JVNVU#93754811 CISA ICS Advisory / ICS Medical Advisory(2026年09月29日)
https://jvn.jp/vu/JVNVU93754811/index.html

2026年9月30日水曜日

30日 水曜日、先負

+ RHSA-2026:73511 Moderate: gawk security update
https://access.redhat.com/errata/RHSA-2026:73511
CVE-2026-40467
CVE-2026-40468

+ RHSA-2026:73425 Important: gdb security update
https://access.redhat.com/errata/RHSA-2026:73425
CVE-2026-13732

+ RHSA-2026:72468 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:72468
CVE-2025-40323
CVE-2026-45942
CVE-2026-46199
CVE-2026-46204
CVE-2026-46230
CVE-2026-63875
CVE-2026-64034
CVE-2026-64556
CVE-2026-68155
CVE-2026-68156
CVE-2026-68159
CVE-2026-68273
CVE-2026-74753

+ RHSA-2026:72448 Important: expat security update
https://access.redhat.com/errata/RHSA-2026:72448
CVE-2026-66046
CVE-2026-93990

+ iOS 27.0.1 and iPadOS 27.0.1 released
https://support.apple.com/en-us/100100

+ About the security content of iOS 26.7.1 and iPadOS 26.7.1
https://support.apple.com/en-us/149226
CVE-2026-86950

+ Google Chrome 154.0.8037.92/.93, 152.0.7977.149 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01807488085.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop_01748636441.html

+ Mozill Firefox 157.0 released
https://www.firefox.com/en-US/firefox/157.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-97 Security Vulnerabilities fixed in Firefox 157
https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/
CVE-2026-100756
CVE-2026-100757
CVE-2026-100758
CVE-2026-100759
CVE-2026-100760
CVE-2026-100761
CVE-2026-100762
CVE-2026-100763
CVE-2026-100764
CVE-2026-100765
CVE-2026-100766
CVE-2026-100767
CVE-2026-100768
CVE-2026-100769
CVE-2026-100770
CVE-2026-100771
CVE-2026-100772
CVE-2026-100773
CVE-2026-100774
CVE-2026-100775
CVE-2026-100776
CVE-2026-100777
CVE-2026-100778
CVE-2026-100779
CVE-2026-100780
CVE-2026-100781
CVE-2026-100782
CVE-2026-100783
CVE-2026-100784
CVE-2026-100785
CVE-2026-100786
CVE-2026-100787
CVE-2026-100788
CVE-2026-100789
CVE-2026-100790
CVE-2026-100791
CVE-2026-100792
CVE-2026-100793
CVE-2026-100794
CVE-2026-96869
CVE-2026-100795
CVE-2026-100796
CVE-2026-100797
CVE-2026-100798
CVE-2026-100799
CVE-2026-100800
CVE-2026-100801
CVE-2026-100802
CVE-2026-100803
CVE-2026-100804
CVE-2026-100805
CVE-2026-100806
CVE-2026-100807
CVE-2026-100808
CVE-2026-100809
CVE-2026-100810
CVE-2026-100811
CVE-2026-100812
CVE-2026-100813
CVE-2026-100814
CVE-2026-100815
CVE-2026-100816
CVE-2026-100817
CVE-2026-100818
CVE-2026-100819
CVE-2026-100820
CVE-2026-100821
CVE-2026-100822
CVE-2026-100823
CVE-2026-100824
CVE-2026-100825
CVE-2026-100826
CVE-2026-100828
CVE-2026-100829
CVE-2026-100830
CVE-2026-100831

+ Mozilla Foundation Security Advisory 2026-100 Security Vulnerabilities fixed in Firefox ESR 153.4
https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/

+ Mozilla Foundation Security Advisory 2026-99 Security Vulnerabilities fixed in Firefox ESR 140.17
https://www.mozilla.org/en-US/security/advisories/mfsa2026-99/

+ Mozilla Foundation Security Advisory 2026-98 Security Vulnerabilities fixed in Firefox ESR 115.42
https://www.mozilla.org/en-US/security/advisories/mfsa2026-98/

+ FreeBSD-SA-26:69.udp IPv6 UDP sendto(2) bypasses jail loopback restriction
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:69.udp.asc
CVE-2026-101303

+ FreeBSD-SA-26:68.openssl Out-of-bounds read in OpenSSL DTLS retransmission
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:68.openssl.asc
CVE-2026-84782

+ FreeBSD-SA-26:67.ktls Remote DoS via receive-side kernel TLS
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:67.ktls.asc
CVE-2026-101302

+ FreeBSD-SA-26:66.jail Multiple jail filesystem root escapes
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:66.jail.asc
CVE-2026-101304
CVE-2026-101305
CVE-2026-101306

+ FreeBSD-SA-26:65.kqueue Memory safety bugs in kqueue copy-on-fork implementation
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:65.kqueue.asc
CVE-2026-58099
CVE-2026-58100

+ FreeBSD-SA-26:64.sysvsem Heap out-of-bounds access in semop(2)
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:64.sysvsem.asc
CVE-2026-58098

+ OpenSSL 4.0.3 released
https://github.com/openssl/openssl/releases/tag/openssl-4.0.3

+ Excessive Memory Allocation in Relative CRLDP Processing
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-35189
CVE-2026-35189

+ QUIC Unvalidated Amplification Credit may be Over Accounted
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-35191
CVE-2026-35191

+ Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-42772
CVE-2026-42772

+ Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54872
CVE-2026-54872

+ QUIC STREAM Fragment Metadata DoS
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54873
CVE-2026-54873

+ Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-54875
CVE-2026-54875

+ Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-72897
CVE-2026-72897

+ QUIC Connection-Level Flow Control is Not Enforced for Streams
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75804
CVE-2026-75804

+ NULL Pointer Dereference in CMP Client Revocation Response Handling
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75805
CVE-2026-75805

+ Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-75806
CVE-2026-75806

+ Timing Side-Channel in SM2 Signature Generation
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-77696
CVE-2026-77696

+ DTLS Retransmits Handshake Messages From a Stale Buffer Offset
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-84782
CVE-2026-84782

+ Use-After-Free in X.509 Extension Cache Under Concurrent Use
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-84783
CVE-2026-84783

+ QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-84784
CVE-2026-84784

+ JVNVU#97703430 ISC BINDにおける複数の脆弱性(2026年9月)
https://jvn.jp/vu/JVNVU97703430/index.html

VU#762428 Authlib library contains a signature?verification bypass vulnerability
https://www.kb.cert.org/vuls/id/762428

データは語る
企業のセキュリティー対策動向 外部委託と内製で方針二分
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/092400234/?ST=nxt_thmit_security

NEWS close-up
ランサム攻撃者の侵入経路に異変
脆弱性悪用を抜き「メール」が首位に 身代金の要求額は平均313万ドル
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/091400342/?ST=nxt_thmit_security

国産セキュリティー製品の勝ち筋
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091400256/091400001/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIが発見した脆弱性は約3万件、修正済みはわずか421件 人手の対応限界に
https://xtech.nikkei.com/atcl/nxt/column/18/00676/091700234/?ST=nxt_thmit_security

ニュース解説
統計数理研がプライバシー保護の新技術、注目集めるTEEの弱点を防止
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12048/?ST=nxt_thmit_security

月刊ランサムリポート
「Dire Wolf」の攻撃が急増、高速な暗号化が特徴 26年8月のランサム被害
https://xtech.nikkei.com/atcl/nxt/column/18/03053/092900023/?ST=nxt_thmit_security

タイムズカー、最大660万件の個人情報が漏洩 免許証に加え学生証も対象
https://xtech.nikkei.com/atcl/nxt/news/24/03399/?ST=nxt_thmit_security

ダークサイドAI
AIの闇落ちを防ぐ 弱点をあぶり出せ[Part 5]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700005/?ST=nxt_thmit_security

ダークサイドAI
スキル形成を阻害 「丸投げ」は厳禁[Part 4]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700004/?ST=nxt_thmit_security

ダークサイドAI
脆弱性の嵐が始まる 担当者が燃え尽きる[Part 3]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700003/?ST=nxt_thmit_security

ダークサイドAI
AI利用で思考力低下 粘り強さもなくなる[Part 2]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700002/?ST=nxt_thmit_security

ダークサイドAI
AIエージェント暴走 本番データを全削除[Part 1]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/091700571/091700001/?ST=nxt_thmit_security

日経NETWORK 特別リポート
どうするSCS評価制度
開始見込みまであと半年
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800013/091400107/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
さくらインターネットに不正アクセス、136万超の会員情報に影響
https://xtech.nikkei.com/atcl/nxt/column/18/00598/011300383/?ST=nxt_thmit_security

JVNVU#96968110 PFU製Image Scanner Driver for Linuxにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96968110/index.html

JVN#22475874 Pgpool-IIにおける複数の脆弱性
https://jvn.jp/jp/JVN22475874/index.html

JVNVU#99151548 Authlibライブラリにおける署名検証が回避される脆弱性
https://jvn.jp/vu/JVNVU99151548/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

JVNVU#94863997 バッファロー製Wi-Fi製品における複数の脆弱性
https://jvn.jp/vu/JVNVU94863997/index.html

JVNVU#96520526 Androidアプリ「Readwise Reader」における複数のクロスサイトスクリプティングの脆弱性
https://jvn.jp/vu/JVNVU96520526/index.html

2026年9月28日月曜日

28日 月曜日、先勝

VU#699627 Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
https://www.kb.cert.org/vuls/id/699627

NEWS close-up
富士通がAI時代のサイバー防衛戦略
「減速防御」掲げ年内にもサービス化 100人規模のバーチャル組織で対応
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/091400338/?ST=nxt_thmit_security

北郷達郎のテクノロジー温故知新
30年以上続く「Delphi」に新版登場、ただ開発ツールの先行きは厳しい
https://xtech.nikkei.com/atcl/nxt/column/18/02598/091500037/?ST=nxt_thmit_security

国税庁の「KSK2」、手続き遅れ解消せず 納税証明書は旧システムで処理
https://xtech.nikkei.com/atcl/nxt/news/24/03396/?ST=nxt_thmit_security

2026年9月25日金曜日

25日 金曜日、仏滅

+ Gpg4win 5.1.1 released
https://www.gpg4win.org/change-history.html

+ RHSA-2026:71652 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:71652
CVE-2026-92005
CVE-2026-92006
CVE-2026-92007
CVE-2026-92008
CVE-2026-92009
CVE-2026-92010
CVE-2026-92011
CVE-2026-92012
CVE-2026-92013
CVE-2026-92014
CVE-2026-92015
CVE-2026-92016
CVE-2026-92017
CVE-2026-92018
CVE-2026-92019
CVE-2026-92020
CVE-2026-92021
CVE-2026-92022
CVE-2026-92023
CVE-2026-92024
CVE-2026-92025
CVE-2026-92026
CVE-2026-92027
CVE-2026-92028
CVE-2026-92029
CVE-2026-92030
CVE-2026-92031
CVE-2026-92032

+ RHSA-2026:71641 Important: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:71641
CVE-2026-74860
CVE-2026-86138
CVE-2026-86140
CVE-2026-86143
CVE-2026-86144

+ RHSA-2026:71608 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:71608
CVE-2026-73194

+ RHSA-2026:71213 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:71213
CVE-2026-43370
CVE-2026-63831
CVE-2026-64564
CVE-2026-72261
CVE-2026-80844
CVE-2026-81000
CVE-2026-89846

+ RHSA-2026:70754 Critical: unbound security update
https://access.redhat.com/errata/RHSA-2026:70754
CVE-2026-81634
CVE-2026-81642
CVE-2026-82717

+ RHSA-2026:70630 Moderate: java-1.8.0-ibm security update
https://access.redhat.com/errata/RHSA-2026:70630
CVE-2026-16440
CVE-2026-60589
CVE-2026-61308
CVE-2026-70907

+ RHSA-2026:70402 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:70402
CVE-2023-54120
CVE-2023-54214
CVE-2025-39964
CVE-2025-71082
CVE-2026-43334
CVE-2026-45894
CVE-2026-46043
CVE-2026-46133
CVE-2026-52918
CVE-2026-53053
CVE-2026-53062
CVE-2026-53254
CVE-2026-53256
CVE-2026-63823
CVE-2026-63947
CVE-2026-63975
CVE-2026-64534
CVE-2026-64582
CVE-2026-68188
CVE-2026-68293

+ RHSA-2026:70390 Moderate: tar security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:70390
CVE-2025-45582
CVE-2026-5704
CVE-2026-18477
CVE-2026-18508

+ RHSA-2026:69964 Moderate: coreutils security update
https://access.redhat.com/errata/RHSA-2026:69964
CVE-2025-5278

+ watchOS 27.0.1 released
https://support.apple.com/en-us/100100

+ Google Chrome 155.0.8059.12/.13 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_01050350268.html

+ Mozilla Firefox 156.0.1 released
https://www.firefox.com/en-US/firefox/156.0.1/releasenotes/

+ Zabbix 7.4.15, 7.0.31 released
https://www.zabbix.com/rn/rn7.4.15
https://www.zabbix.com/rn/rn7.0.31

+ Mozilla Thunderbird 156.0.1 released
https://www.thunderbird.net/en-US/thunderbird/156.0.1/releasenotes/

+ Wireshark 4.6.9, 4,4,19 released
https://www.wireshark.org/docs/relnotes/wireshark-4.6.9.html
https://www.wireshark.org/docs/relnotes/wireshark-4.4.19.html

+ PHP 8.5.11, 8.4.26, 8.3.35, 8.2.34 released
https://www.php.net/ChangeLog-8.php#8.5.11
https://www.php.net/ChangeLog-8.php#8.4.26
https://www.php.net/ChangeLog-8.php#8.3.35
https://www.php.net/ChangeLog-8.php#8.2.34

+ Apache Tomcatの脆弱性(Critical: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, High: CVE-2026-75973, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-87022, Medium: CVE-2026-73581, Low: CVE-2026-77756)
https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260924/
CVE-2026-76183
CVE-2026-86248
CVE-2026-86350
CVE-2026-75973
CVE-2026-77762
CVE-2026-77791
CVE-2026-78383
CVE-2026-78437
CVE-2026-79677
CVE-2026-87022
CVE-2026-73581
CVE-2026-77756

VU#234131 ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
https://www.kb.cert.org/vuls/id/234131

VU#676317 Norwegian Cruise Line door access controller contains an improper authentication vulnerability
https://www.kb.cert.org/vuls/id/676317

VU#273940 Enterprise Access Management EAM does not rotate RSA keys
https://www.kb.cert.org/vuls/id/273940

VU#754548
Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi?user chat handlers
https://www.kb.cert.org/vuls/id/754548

VU#738147 Vendor-signed UEFI Shell applications allow Secure Boot bypass
https://www.kb.cert.org/vuls/id/738147

piyokangoの月刊システムトラブル
全日空商事でギフト不正交換 原因は第三者の不正アクセス
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/091400091/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
ディープフェイクを訓練で見抜く 整い過ぎた顔や高画質がヒント
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/091700195/?ST=nxt_thmit_security

日経コンピュータ 中田敦のGAFA深読み
メタの新AIエージェント「Muse」 機密コンピューティングに注目
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100111/092400186/?ST=nxt_thmit_security

JVN#21754394 baserCMS用プラグイン「アドオンマイグレーター」 における信頼できない制御領域からの機能の組み込みに関する脆弱性
https://jvn.jp/jp/JVN21754394/index.html

JVN#14353754 baserCMSにおける複数の脆弱性
https://jvn.jp/jp/JVN14353754/index.html

JVNVU#96941087 ViewSonic vCastにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96941087/index.html

JVNVU#96565230 Norwegian Cruise Lineのドアアクセスコントローラにおける認証不備の脆弱性
https://jvn.jp/vu/JVNVU96565230/index.html

JVNVU#93222287 CISA ICS Advisory / ICS Medical Advisory(2026年09月24日)
https://jvn.jp/vu/JVNVU93222287/index.html

2026年9月21日月曜日

21日 月曜日、赤口

+ RHSA-2026:69095 Important: libtiff security update
https://access.redhat.com/errata/RHSA-2026:69095
CVE-2026-52490

+ RHSA-2026:69100 Important: gstreamer1-plugins-base security update
https://access.redhat.com/errata/RHSA-2026:69100
CVE-2026-18297
CVE-2026-85150

+ JVNVU#97703430 ISC BINDにおける複数の脆弱性(2026年9月)
https://jvn.jp/vu/JVNVU97703430/index.html
CVE-2026-19033
CVE-2026-19662
CVE-2026-19666
CVE-2026-19667
CVE-2026-19668
CVE-2026-19941
CVE-2026-75029
CVE-2026-76163
CVE-2026-77119
CVE-2026-77692
CVE-2026-78301
CVE-2026-80274
CVE-2026-81563
CVE-2026-81736

2026年9月18日金曜日

18日 金曜日、先負

+ RHSA-2026:68787 Important: perl-Net-DNS security update
https://access.redhat.com/errata/RHSA-2026:68787
CVE-2026-81928

+ RHSA-2026:68676 Important: .NET 10.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68676
CVE-2026-58649
CVE-2026-69806

+ RHSA-2026:68549 Important: firefox security update
https://access.redhat.com/errata/RHSA-2026:68549
CVE-2026-16365
CVE-2026-75874
CVE-2026-84119
CVE-2026-84120
CVE-2026-84121
CVE-2026-84122
CVE-2026-84124
CVE-2026-84131
CVE-2026-84143
CVE-2026-84145

+ RHSA-2026:68660 Moderate: tomcat security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68660
CVE-2026-32990
CVE-2026-41293
CVE-2026-42498
CVE-2026-43512
CVE-2026-43513
CVE-2026-43515
CVE-2026-59083
CVE-2026-59084

+ Google Chrome 153.0.8010.52/.53, 152.0.7977.134 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop_0130771745.html

AlmaLinux 9.9 Beta Now Available!
https://almalinux.org/blog/2026-09-17-announcing-99-beta/

VU#280377 Dokploy is vulnerable to OS command injection
https://www.kb.cert.org/vuls/id/280377

ITが危ない
「ダークパターン」に法規制の動き、悪質な勧誘や解約妨害は業務停止命令も
https://xtech.nikkei.com/atcl/nxt/column/18/00989/091400220/?ST=nxt_thmit_security

SCSKが伴走型セキュリティーサービス開始、生成AIで増える脅威へ備え
https://xtech.nikkei.com/atcl/nxt/news/24/03389/?ST=nxt_thmit_security

JVN#93985674 スマートフォンアプリ「東北電力 よりそうeねっと」におけるハードコードされた暗号鍵使用の脆弱性
https://jvn.jp/jp/JVN93985674/index.html

JVNVU#94390979 MLflowのdspyとstatsmodelsフレーバーにおけるpickleのデシリアライズ制御回避の脆弱性
https://jvn.jp/vu/JVNVU94390979/index.html

JVNVU#91019649 Sentry Seerにおける攻撃者が制御する入力が管理者権限で実行される脆弱性
https://jvn.jp/vu/JVNVU91019649/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

2026年9月17日木曜日

17日 木曜日、友引

+ RHSA-2026:68316 Moderate: .NET 8.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68316
CVE-2026-58649

+ RHSA-2026:68233 Important: .NET 9.0 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:68233
CVE-2026-58649
CVE-2026-69806

+ RHSA-2026:67943 Important: python-lxml security update
https://access.redhat.com/errata/RHSA-2026:67943
CVE-2026-49825

+ RHSA-2026:67908 Important: libevent security update
https://access.redhat.com/errata/RHSA-2026:67908
CVE-2026-63382
CVE-2026-63383
CVE-2026-63384
CVE-2026-63385
CVE-2026-63387
CVE-2026-63388

+ RHSA-2026:67832 Important: tesseract security update
https://access.redhat.com/errata/RHSA-2026:67832
CVE-2026-73066

+ Google Chrome 154.0.8037.44/.45 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_096324202.html

+ Mozilla Foundation Security Advisory 2026-96 Security Vulnerabilities fixed in Thunderbird 153.3
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/

+ ISC BIND 9.21.26, 9.20.29 released
https://downloads.isc.org/isc/bind9/9.21.26/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.20.29/doc/arm/html/notes.html

+ BIND 9の脆弱性(High: CVE-2026-19666, CVE-2026-19667, CVE-2026-76163, CVE-2026-77692, CVE-2026-80274, CVE-2026-81563, CVE-2026-81736, Medium: CVE-2026-19033, CVE-2026-19662, CVE-2026-19668, CVE-2026-19941, CVE-2026-75029, CVE-2026-77119, CVE-2026-78301)と修正バージョン(9.20.29, 9.21.26)
https://security.sios.jp/vulnerability/bind9-security-vulnerability-20260917/
CVE-2026-19666
CVE-2026-19667
CVE-2026-76163
CVE-2026-77692
CVE-2026-80274
CVE-2026-81563
CVE-2026-81736
CVE-2026-19033
CVE-2026-19662
CVE-2026-19668
CVE-2026-19941
CVE-2026-75029
CVE-2026-77119
CVE-2026-78301

VU#369093 MLflow dspy and statsmodels flavors bypass pickle deserialization control
https://www.kb.cert.org/vuls/id/369093

VU#212479 Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
https://www.kb.cert.org/vuls/id/212479

ニュース&リポート
SBOM最小要素、26年版で増加 日本では「推奨」、強制せず
作成負荷増も、運用の自動化にはメリット
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/091001497/?ST=nxt_thmit_security

生成AI時代のOSS危機 第4回
OSSのAI再実装は悪か、波紋呼ぶ「ライセンス洗浄」と貢献の行方
https://xtech.nikkei.com/atcl/nxt/column/18/03754/091100003/?ST=nxt_thmit_security

JVN#95825631 QNDにおける複数の脆弱性
https://jvn.jp/jp/JVN95825631/index.html

JVN#45281119 XikeStor製Layer3スイッチのコンフィグレーションデータダウンロード機能における認証欠如の脆弱性
https://jvn.jp/jp/JVN45281119/index.html

JVNVU#93448623 CISA ICS Advisory / ICS Medical Advisory(2026年09月15日)
https://jvn.jp/vu/JVNVU93448623/index.html

2026年9月16日水曜日

16日 水曜日、先勝

+ RHSA-2026:67468 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:67468
CVE-2024-53161
CVE-2025-71127
CVE-2026-43133
CVE-2026-52947
CVE-2026-53182
CVE-2026-63802
CVE-2026-63889
CVE-2026-64117
CVE-2026-68363
CVE-2026-72098
CVE-2026-74556

+ RHSA-2026:67315 Moderate: nginx:1.24 security update
https://access.redhat.com/errata/RHSA-2026:67315
CVE-2026-42533

+ RHSA-2026:67278 Moderate: perl:5.32 security update
https://access.redhat.com/errata/RHSA-2026:67278
CVE-2026-13221

+ RHSA-2026:67266 Moderate: libkcapi security update
https://access.redhat.com/errata/RHSA-2026:67266
CVE-2026-71225
CVE-2026-71226
CVE-2026-71227

+ About the security content of iOS 27 and iPadOS 27
https://support.apple.com/en-us/149034
CVE-2026-86882
CVE-2026-43664
CVE-2026-64761
CVE-2026-65404
CVE-2026-84523
CVE-2026-86888
CVE-2026-20683
CVE-2026-65408
CVE-2026-65407
CVE-2026-84519
CVE-2026-84593
CVE-2026-86905
CVE-2026-84583
CVE-2026-65410
CVE-2026-84616
CVE-2026-84607
CVE-2026-65406
CVE-2026-86885
CVE-2026-86879
CVE-2026-65414
CVE-2026-84560
CVE-2026-86878
CVE-2026-86895
CVE-2026-86893
CVE-2026-65399
CVE-2026-64752
CVE-2026-86876
CVE-2026-65344
CVE-2026-84624
CVE-2026-43737
CVE-2026-65412
CVE-2026-84596
CVE-2026-84575
CVE-2026-84489
CVE-2026-84571
CVE-2026-43738
CVE-2026-84511
CVE-2026-84612
CVE-2026-84552
CVE-2026-84510
CVE-2026-43785
CVE-2026-84534
CVE-2026-43688
CVE-2026-84524
CVE-2026-84597
CVE-2026-65409
CVE-2026-84492
CVE-2026-84533
CVE-2026-84606
CVE-2026-64756
CVE-2026-84564
CVE-2026-65395
CVE-2026-28969
CVE-2026-65398
CVE-2026-64760
CVE-2026-65354
CVE-2026-28968
CVE-2026-84566
CVE-2026-65415
CVE-2026-84561
CVE-2026-84630
CVE-2026-65360
CVE-2026-65358
CVE-2026-65377
CVE-2026-84622
CVE-2026-43689
CVE-2026-43687
CVE-2026-43686
CVE-2026-65405
CVE-2026-84530
CVE-2026-84521
CVE-2026-65402
CVE-2026-65359
CVE-2026-84507
CVE-2026-86903
CVE-2026-84602
CVE-2026-86870
CVE-2026-86883
CVE-2026-84628
CVE-2026-86924
CVE-2026-65411
CVE-2026-84598
CVE-2026-84497
CVE-2026-84615
CVE-2026-43695
CVE-2026-84626
CVE-2026-84491
CVE-2026-84629
CVE-2026-84623
CVE-2026-28966
CVE-2026-84532
CVE-2026-65403
CVE-2026-84518
CVE-2026-86897
CVE-2026-84551
CVE-2026-84625
CVE-2026-84603
CVE-2026-84487
CVE-2026-84632
CVE-2026-84620
CVE-2026-84546
CVE-2026-84611
CVE-2026-84526
CVE-2026-86881
CVE-2026-84531
CVE-2026-84600
CVE-2026-86884
CVE-2026-86890
CVE-2026-84609
CVE-2026-84621
CVE-2026-86892
CVE-2026-65348
CVE-2026-65345
CVE-2026-84513
CVE-2026-86886
CVE-2026-84527
CVE-2026-65329
CVE-2026-86887
CVE-2026-86904
CVE-2026-84635
CVE-2026-64753
CVE-2026-86898
CVE-2026-64718
CVE-2026-43674
CVE-2026-84636
CVE-2026-84617

+ About the security content of iOS 26.7 and iPadOS 26.7
https://support.apple.com/en-us/149041

+ About the security content of macOS Golden Gate 27
https://support.apple.com/en-us/149035

+ About the security content of macOS Tahoe 26.7
https://support.apple.com/en-us/149042

+ About the security content of macOS Sequoia 15.8
https://support.apple.com/en-us/149043

+ About the security content of tvOS 27
https://support.apple.com/en-us/149036

+ About the security content of watchOS 27
https://support.apple.com/en-us/149037

+ About the security content of visionOS 27
https://support.apple.com/en-us/149038

+ About the security content of Safari 27
https://support.apple.com/en-us/149039

+ About the security content of Xcode 27
https://support.apple.com/en-us/149040

+ Google Chrome 153.0.8010.47/.48, 152.0.7977.130 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop_01936140552.html

+ Mozill Firefox 156.0 released
https://www.firefox.com/en-US/firefox/156.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-90 Security Vulnerabilities fixed in Firefox 156
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/
CVE-2026-92033
CVE-2026-92005
CVE-2026-92006
CVE-2026-92007
CVE-2026-92008
CVE-2026-92009
CVE-2026-92010
CVE-2026-92011
CVE-2026-92012
CVE-2026-92013
CVE-2026-92015
CVE-2026-92034
CVE-2026-92035
CVE-2026-92016
CVE-2026-92017
CVE-2026-92018
CVE-2026-92019
CVE-2026-92020
CVE-2026-92022
CVE-2026-92023
CVE-2026-92024
CVE-2026-92025
CVE-2026-92026
CVE-2026-92036
CVE-2026-92027
CVE-2026-92028
CVE-2026-92029
CVE-2026-92037
CVE-2026-92038
CVE-2026-92039
CVE-2026-92040
CVE-2026-92041
CVE-2026-92042
CVE-2026-92043
CVE-2026-92044
CVE-2026-92045
CVE-2026-92030
CVE-2026-92046
CVE-2026-92047
CVE-2026-92048
CVE-2026-92049
CVE-2026-92050
CVE-2026-92051
CVE-2026-92052
CVE-2026-92053
CVE-2026-92054
CVE-2026-92055
CVE-2026-92056
CVE-2026-92057
CVE-2026-92031
CVE-2026-92032
CVE-2026-92058
CVE-2026-92059
CVE-2026-92060
CVE-2026-92061
CVE-2026-92062
CVE-2026-92063
CVE-2026-92064
CVE-2026-92065
CVE-2026-92066
CVE-2026-92067
CVE-2026-92068
CVE-2026-92069
CVE-2026-92070
CVE-2026-92071
CVE-2026-92072
CVE-2026-92073
CVE-2026-92074
CVE-2026-92075
CVE-2026-92076
CVE-2026-92077
CVE-2026-92078
CVE-2026-92079

+ Mozilla Foundation Security Advisory 2026-93 Security Vulnerabilities fixed in Firefox ESR 153.3
https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/

+ Mozilla Foundation Security Advisory 2026-92 Security Vulnerabilities fixed in Firefox ESR 140.16
https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/

+ Mozilla Foundation Security Advisory 2026-91 Security Vulnerabilities fixed in Firefox ESR 115.41
https://www.mozilla.org/en-US/security/advisories/mfsa2026-91/

+ Mozilla Thunderbird 156.0 released
https://www.thunderbird.net/en-US/thunderbird/156.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-94 Security Vulnerabilities fixed in Thunderbird 156
https://www.mozilla.org/en-US/security/advisories/mfsa2026-94/

+ Mozilla Foundation Security Advisory 2026-95 Security Vulnerabilities fixed in Thunderbird 140.16
https://www.mozilla.org/en-US/security/advisories/mfsa2026-95/

+ nginx 1.31.6, 1.30.5 released
https://nginx.org/en/CHANGES
https://nginx.org/en/CHANGES-1.30

+ K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439
https://my.f5.com/manage/s/article/K000162604
CVE-2026-90439

+ Apache Tomcat 11.0.26, 10.1.60, 9.0.122 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.26_(markt)
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.60_(schultz)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.122_(remm)

JVN#72918755 Androidアプリ「【保護者専用】まなびポケット」におけるアクセス制限不備の脆弱性
https://jvn.jp/jp/JVN72918755/index.html

JVN#02049764 Lite-On製O-RU「FF-RFI079I4」および「FF-RFI078I4」における複数の脆弱性
https://jvn.jp/jp/JVN02049764/index.html

JVNVU#99837984 パナソニック インダストリー製MINAS A5/A6用Windows USBデバイスドライバにおけるバッファオーバーフローの脆弱性
https://jvn.jp/vu/JVNVU99837984/index.html

JVNVU#99009004 コンテック製無線LAN FLEXLANシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99009004/index.html

JVN#69877538 Androidアプリ「YAMAP / ヤマップ登山地図アプリ」におけるアクセス制限不備の脆弱性
https://jvn.jp/jp/JVN69877538/index.html

JVNVU#94022278 ExLlamaV3のexllamav3_extモジュールにおける不適切な入力検証の脆弱性
https://jvn.jp/vu/JVNVU94022278/index.html

勝村幸博の「今日も誰かが狙われる」
ディープフェイク画像を15分の訓練で見抜く、あなたも挑戦してみよう
https://xtech.nikkei.com/atcl/nxt/column/18/00676/091000233/?ST=nxt_thmit_security

生成AI時代のOSS危機 第3回
OSS保守を襲う「AIスロップ」、変更提案1日200件 サプライチェーン攻撃も
https://xtech.nikkei.com/atcl/nxt/column/18/03754/091100004/?ST=nxt_thmit_security

ニュース解説
Java 27のTLS機能で耐量子暗号が利用可能に、過去のLTS版にも遡って実装
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12033/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
RIZAPで「シャドーAI」、社員が顧客情報を誤投入 委託元が約2万人分被害
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900381/?ST=nxt_thmit_security

生成AI時代のOSS危機 第2回
Anthropic「Mythos」、18時間で8件の攻撃手法を構築 OSS防御は追いつくか
https://xtech.nikkei.com/atcl/nxt/column/18/03754/091000002/?ST=nxt_thmit_security

2026年9月14日月曜日

14日 月曜日、大安

+ ■Windows DNSの脆弱性情報が公開されました(CVE-2026-69730、他17件)
https://jprs.jp/tech/security/2026-09-11-windowsdns.html

VU#369611 ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
https://www.kb.cert.org/vuls/id/369611

JVN#20829034 a-blog cmsにおけるパストラバーサルの脆弱性
https://jvn.jp/jp/JVN20829034/index.html

JVNVU#94404414 CISA ICS Advisory / ICS Medical Advisory(2026年09月10日)
https://jvn.jp/vu/JVNVU94404414/index.html

JVNVU#95258183 AOMEI Backupperのamwrtdrv.sysカーネルドライバにおける権限昇格の脆弱性
https://jvn.jp/vu/JVNVU95258183/index.html

生成AI時代のOSS危機 第1回
提供と利用の双方に「OSSの危機」、AIで増幅 知らないこと自体がリスク
https://xtech.nikkei.com/atcl/nxt/column/18/03754/090900001/?ST=nxt_thmit_security

日経クロステックNEXT 東京 2026特集
AIエージェントによる攻撃出現、VPN以外も標的に ランサム攻撃の最新動向
https://xtech.nikkei.com/atcl/nxt/column/18/03745/090800007/?ST=nxt_thmit_security

国の機関の業務環境GSSに不正侵入、職員の氏名など24万6000件漏洩の恐れ
https://xtech.nikkei.com/atcl/nxt/news/24/03383/?ST=nxt_thmit_security

2026年9月11日金曜日

11日 金曜日、友引

+ RHSA-2026:66348 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:66348
CVE-2026-28420
CVE-2026-52859
CVE-2026-55892
CVE-2026-59857
CVE-2026-73072
CVE-2026-73076
CVE-2026-73078

+ RHSA-2026:66325 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:66325
CVE-2025-68745
CVE-2026-46149
CVE-2026-52917
CVE-2026-52942
CVE-2026-52986
CVE-2026-53091
CVE-2026-53246
CVE-2026-63801
CVE-2026-63971
CVE-2026-64015
CVE-2026-64113
CVE-2026-68117
CVE-2026-68300
CVE-2026-68315
CVE-2026-68376

+ RHSA-2026:66542 Important: nginx security update
https://access.redhat.com/errata/RHSA-2026:66542
CVE-2026-42533

+ RHSA-2026:66403 Moderate: coreutils security update
https://access.redhat.com/errata/RHSA-2026:66403
CVE-2026-56392

+ RHSA-2026:66401 Important: Red Hat OpenStack Platform 17.1 security and bug fix advisory
https://access.redhat.com/errata/RHSA-2026:66401
CVE-2025-61726
CVE-2025-68121
CVE-2026-24708
CVE-2026-25679
CVE-2026-32280
CVE-2026-32282
CVE-2026-32283

+ RHSA-2026:66366 Important: vim security update
https://access.redhat.com/errata/RHSA-2026:66366
CVE-2026-28420
CVE-2026-52859
CVE-2026-55892
CVE-2026-59857
CVE-2026-73072
CVE-2026-73076
CVE-2026-73077
CVE-2026-73078

+ RHSA-2026:66341 Moderate: apr-util security update
https://access.redhat.com/errata/RHSA-2026:66341
CVE-2025-49506
CVE-2026-32327
CVE-2026-34501
CVE-2026-34502

+ 2026 年 9 月のセキュリティ更新プログラム (月例)
https://www.microsoft.com/en-us/msrc/blog/2026/09/202609-security-update

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
AIエージェント同士が縄張り争い 矛盾した指示によるリスク判明
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/090700194/?ST=nxt_thmit_security

UPDATE: JVNVU#90314828 コンテック製PC-HELPERシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90314828/index.html

JVNVU#96551518 コンテック製CONPROSYSシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96551518/index.html

JVNVU#99009004 コンテック製無線LAN FLEXLANシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99009004/index.html

JVNVU#97753461 コンテック製SolarView Compactにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97753461/index.html

JVN#37476837 SHIRASAGIにおける複数の脆弱性
https://jvn.jp/jp/JVN37476837/index.html

VU#687587 AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
https://www.kb.cert.org/vuls/id/687587

2026年9月10日木曜日

10日 木曜日、大安

+ RHSA-2026:66248 Important: ansible-core security update
https://access.redhat.com/errata/RHSA-2026:66248
CVE-2026-11332

+ RHSA-2026:66016 Important: osbuild-composer security update
https://access.redhat.com/errata/RHSA-2026:66016
CVE-2024-9355
CVE-2024-45336
CVE-2026-33818
CVE-2026-39820
CVE-2026-39821
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:66000 Important: kernel security update
https://access.redhat.com/errata/RHSA-2026:66000
CVE-2026-43493
CVE-2026-53002
CVE-2026-64007
CVE-2026-64563
CVE-2026-68343
CVE-2026-72129
CVE-2026-74480

+ RHSA-2026:65998 Moderate: gzip security update
https://access.redhat.com/errata/RHSA-2026:65998
CVE-2026-41991
CVE-2026-41992

+ RHSA-2026:65897 Important: qt5-qtbase security update
https://access.redhat.com/errata/RHSA-2026:65897
CVE-2026-9499

+ RHSA-2026:65832 Important: mrtg security update
https://access.redhat.com/errata/RHSA-2026:65832
CVE-2026-72694

+ RHSA-2026:66204 Important: python-lxml security update
https://access.redhat.com/errata/RHSA-2026:66204
CVE-2026-49825

+ RHSA-2026:66203 Important: python3.12-lxml security update
https://access.redhat.com/errata/RHSA-2026:66203
CVE-2026-49825

+ RHSA-2026:66179 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:66179
CVE-2026-19546

+ RHSA-2026:65993 Important: qt5-qtbase security update
https://access.redhat.com/errata/RHSA-2026:65993
CVE-2026-9499

+ RHSA-2026:65886 Important: image-builder security update
https://access.redhat.com/errata/RHSA-2026:65886
CVE-2026-32280
CVE-2026-32281
CVE-2026-33811
CVE-2026-33818
CVE-2026-39820
CVE-2026-39821
CVE-2026-42499
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ Google Chrome 154.0.8037.17/.18, 152.0.7977.120 released
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop_01157104879.html
https://chromereleases.googleblog.com/2026/09/extended-stable-update-for-desktop.html

+ Mozill Thunderbird 155.0.1 released
https://www.thunderbird.net/en-US/thunderbird/155.0.1/releasenotes/

JVN#21088484 baserCMS用プラグイン「BurgerEditor」における複数の脆弱性
https://jvn.jp/jp/JVN21088484/index.html

JVNVU#93257103 CISA ICS Advisory / ICS Medical Advisory(2026年09月08日)
https://jvn.jp/vu/JVNVU93257103/index.html

JVNVU#94974158 SPI Flashに組み込まれたUEFI Shellモジュールにおけるセキュアブート回避の脆弱性
https://jvn.jp/vu/JVNVU94974158/index.html

JVNVU#94533753 Ascensio System SIA製ONLYOFFICE ownCloud統合プラグインにおけるサーバサイドリクエストフォージェリの脆弱性
https://jvn.jp/vu/JVNVU94533753/index.html

JVNVU#91877671 Skullcandy製ワイヤレスイヤホン「Dime 3」における不適切な認証の脆弱性
https://jvn.jp/vu/JVNVU91877671/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

2026年9月9日水曜日

9日 水曜日、仏滅

+ RHSA-2026:65160 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2026:65160
CVE-2026-74934
CVE-2026-74935
CVE-2026-74939
CVE-2026-74940
CVE-2026-74941
CVE-2026-74942
CVE-2026-74945
CVE-2026-74946
CVE-2026-74948
CVE-2026-74953
CVE-2026-74957
CVE-2026-74959
CVE-2026-74960
CVE-2026-74962
CVE-2026-74963
CVE-2026-74964
CVE-2026-74965
CVE-2026-74967
CVE-2026-74971
CVE-2026-74972
CVE-2026-74973
CVE-2026-74974
CVE-2026-74976
CVE-2026-74987
CVE-2026-74990

+ RHSA-2026:65147 Important: microcode_ctl security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:65147
CVE-2025-31936
CVE-2025-35973

+ RHSA-2026:64823 Important: redis:6 security update
https://access.redhat.com/errata/RHSA-2026:64823
CVE-2026-66373
CVE-2026-81934

+ RHSA-2026:65606 Important: gpsd-minimal security update
https://access.redhat.com/errata/RHSA-2026:65606
CVE-2026-60122

+ RHSA-2026:65117 Important: opentelemetry-collector security update
https://access.redhat.com/errata/RHSA-2026:65117
CVE-2026-33818
CVE-2026-39820
CVE-2026-41178
CVE-2026-42499
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:64824 Important: redis security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:64824
CVE-2026-66373
CVE-2026-81934

+ RHSA-2026:64774 Important: python3.14-cryptography security update
https://access.redhat.com/errata/RHSA-2026:64774
CVE-2026-69248
CVE-2026-69249

+ iOS 26.6.2 and iPadOS 26.6.2 released
https://support.apple.com/en-us/100100

+ Google Chrome 153.0.8010.36/.37 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html

+ FreeBSD 14.5-RELEASE released
https://www.freebsd.org/releases/14.5R/relnotes/

+ Apache Tomcat Native 2.0.16, 1.3.9 released
https://tomcat.apache.org/native-doc/miscellaneous/changelog.html#2.0.16
https://tomcat.apache.org/native-1.3-doc/miscellaneous/changelog.html#1.3.9

+ OpenLDAP-2.7.1, 2.6.15 released
https://www.openldap.org/software/release/changes.html
https://www.openldap.org/software/release/changes_lts.html

+ Postfix stable release 3.11.7 and legacy releases 3.10.14, 3.9.15, 3.8.21, 3.7.23, 3.6.21, 3.5.28 released
https://www.postfix.org/announcements/postfix-3.11.7.html

■Knot DNSの脆弱性情報が公開されました
https://jprs.jp/tech/security/2026-09-08-knotdns.html

VU#718077 UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
https://www.kb.cert.org/vuls/id/718077

VU#859658 Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
https://www.kb.cert.org/vuls/id/859658

VU#943094 ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
https://www.kb.cert.org/vuls/id/943094

ニュース解説
スマホで法人代表者の実印、「商業登記リモート署名」開始 民間と競合も
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12018/?ST=nxt_thmit_security

全日空商事「選べるe-GIFT」で不正交換、管理システムに第三者がアクセス
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900380/?ST=nxt_thmit_security

2026年9月7日月曜日

7日 月曜日、友引

+ Mozilla Firefox 155.0.1 released
https://www.firefox.com/en-US/firefox/155.0.1/releasenotes/

+ Apache Ant 1.10.18 Released
https://ant.apache.org/bindownload.cgi

+ Windows Defender (MsMpEng.exe) Race Condition
https://cxsecurity.com/issue/WLB-2026090007

+ ProFTPD mod_sql post-authentication SQLi RCE
https://cxsecurity.com/issue/WLB-2026090006
CVE-2026-42167

JVN#32505330 エクシングCPTrans-ME-Xにおける複数の脆弱性
https://jvn.jp/jp/JVN32505330/index.html

JVNVU#94249914 CISA ICS Advisory / ICS Medical Advisory(2026年09月03日)
https://jvn.jp/vu/JVNVU94249914/index.html

JVNVU#96680494 Casdoorにおける認可回避の脆弱性
https://jvn.jp/vu/JVNVU96680494/index.html

JVNVU#97027767 Siemens製品に対するアップデート(2026年9月)
https://jvn.jp/vu/JVNVU97027767/index.html

2026年9月4日金曜日

4日 金曜日、大安

+ domain-scoped PSL domain cookie
https://curl.se/docs/CVE-2026-82209.html
CVE-2026-82209

+ wolfSSL CA-cache hit overrides callback
https://curl.se/docs/CVE-2026-82208.html
CVE-2026-82208

+ secure cookie attribute bypass with tab
https://curl.se/docs/CVE-2026-80255.html
CVE-2026-80255

+ native CA store conn reuse
https://curl.se/docs/CVE-2026-80231.html
CVE-2026-80231

+ OpenSSL pinning bypass
https://curl.se/docs/CVE-2026-80230.html
CVE-2026-80230

+ OpenSSL provider use-after-free
https://curl.se/docs/CVE-2026-80229.html
CVE-2026-80229

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ Negotiate ambient user conn reuse
https://curl.se/docs/CVE-2026-19931.html
CVE-2026-19931

+ HTTP/2 server push UAF
https://curl.se/docs/CVE-2026-18924.html
CVE-2026-18924

+ OpenLDAP SASL authentication bypass
https://curl.se/docs/CVE-2026-13608.html
CVE-2026-13608

+ RHSA-2026:63124 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63124
CVE-2026-33818
CVE-2026-42504
CVE-2026-56853
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63014 Important: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:63014
CVE-2024-57849
CVE-2025-71132
CVE-2026-45970
CVE-2026-53185
CVE-2026-53391
CVE-2026-53392
CVE-2026-53397
CVE-2026-53399
CVE-2026-63800
CVE-2026-64018
CVE-2026-64268
CVE-2026-64298
CVE-2026-68480
CVE-2026-74581

+ RHSA-2026:63387 Important: Satellite 6.17.11 Async Update
https://access.redhat.com/errata/RHSA-2026:63387
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63386 Important: Satellite 6.18.9 Async Update
https://access.redhat.com/errata/RHSA-2026:63386
CVE-2026-10051
CVE-2026-11332
CVE-2026-16493
CVE-2026-34993
CVE-2026-45363
CVE-2026-54512
CVE-2026-68494
CVE-2026-69243
CVE-2026-69244

+ RHSA-2026:63136 Important: grafana-pcp security update
https://access.redhat.com/errata/RHSA-2026:63136
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:63130 Important: rhc security update
https://access.redhat.com/errata/RHSA-2026:63130
CVE-2026-33818
CVE-2026-56858
CVE-2026-56860
CVE-2026-56862

+ Google Chrome 153.0.8010.27/.28, 152.0.7977.82/.83 relased
https://chromereleases.googleblog.com/2026/09/early-stable-update-for-desktop.html
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html

+ UPDATE: JVNVU#96149019 Apache Tomcatにおける複数の脆弱性(2026年8月25日)
https://jvn.jp/vu/JVNVU96149019/index.html

+ UPDATE: JVNVU#96558110 OpenSSLにおける脆弱性に対するアップデート(2026年8月25日)
https://jvn.jp/vu/JVNVU96558110/index.html

+ UPDATE: JVNVU#92139835 OpenSSLのOCSPレスポンス検証におけるクライアント側のメモリリークの脆弱性(CVE-2026-54876)
https://jvn.jp/vu/JVNVU92139835/index.html

+ UPDATE: JVNVU#99139115 Apache TomcatのWebSocket chatサンプルにおけるサービス運用妨害(DoS)の脆弱性(2026年7月28日)
https://jvn.jp/vu/JVNVU99139115/index.html

+ UPDATE: JVNVU#97496543 ISC BINDにおける複数の脆弱性(2026年7月)
https://jvn.jp/vu/JVNVU97496543/index.html

+ UPDATE: JVNVU#95286373 Apache Tomcatにおける複数の脆弱性(2026年7月14日)
https://jvn.jp/vu/JVNVU95286373/index.html

VU#889462 Casdoor authentication server is vulnerable to authorization bypass
https://www.kb.cert.org/vuls/id/889462

2026年9月3日木曜日

3日 木曜日、仏滅

+ RHSA-2026:62667 Important: perl-DBI security update
https://access.redhat.com/errata/RHSA-2026:62667
CVE-2026-9698
CVE-2026-10879
CVE-2026-14380
CVE-2026-14739

+ RHSA-2026:62583 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:62583
CVE-2026-56846
CVE-2026-56848
CVE-2026-58043

+ RHSA-2026:62571 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:62571
CVE-2026-55194
CVE-2026-67288
CVE-2026-67291
CVE-2026-67301

+ RHSA-2026:62507 Important: gimp:2.8 security update
https://access.redhat.com/errata/RHSA-2026:62507
CVE-2026-18301
CVE-2026-18303
CVE-2026-18304
CVE-2026-18305
CVE-2026-18306
CVE-2026-18307
CVE-2026-58380
CVE-2026-66758

+ RHSA-2026:62425 Important: gegl security update
https://access.redhat.com/errata/RHSA-2026:62425
CVE-2026-18300

+ RHSA-2026:62420 Important: gegl04 security update
https://access.redhat.com/errata/RHSA-2026:62420
CVE-2026-18300

+ RHSA-2026:62407 Important: grafana security update
https://access.redhat.com/errata/RHSA-2026:62407
CVE-2026-33818
CVE-2026-39820
CVE-2026-42499
CVE-2026-56853
CVE-2026-56858
CVE-2026-56859
CVE-2026-56860
CVE-2026-56862

+ RHSA-2026:62334 Important: php:7.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:62334
CVE-2026-7260
CVE-2026-17543

+ RHSA-2026:62144 Moderate: wget security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:62144
CVE-2026-58469
CVE-2026-58471
CVE-2026-58472

+ RHSA-2026:62640 Important: kpatch-patch-5_14_0-687_10_1 security update
https://access.redhat.com/errata/RHSA-2026:62640
CVE-2026-43112
CVE-2026-43114
CVE-2026-46323
CVE-2026-52973
CVE-2026-53264

+ RHSA-2026:62217 Moderate: libssh security update
https://access.redhat.com/errata/RHSA-2026:62217
CVE-2026-59843
CVE-2026-59844
CVE-2026-59845
CVE-2026-59846
CVE-2026-59847
CVE-2026-59848
CVE-2026-59850

+ RHSA-2026:61903 Important: php:8.2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:61903
CVE-2026-7260
CVE-2026-17543

+ nginx 1.31.5 released
https://nginx.org/en/CHANGES

+ Mozilla Thunderbrid 155.0 released
https://www.thunderbird.net/en-US/thunderbird/155.0/releasenotes/

ニュース&リポート
オープンAIが先端AIの安全対策緩和 中国モデルの台頭に危機感
サイバー防御プログラム拡充、一部の個人・組織に提供
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/082701491/?ST=nxt_thmit_security

NECがAnthropicの「Mythos」利用権、社内の脆弱性管理に活用
https://xtech.nikkei.com/atcl/nxt/news/24/03370/?ST=nxt_thmit_security

JVNVU#98062224 キーエンス製XG VisionTerminalおよびXG-X VisionTerminalにおけるにおけるXML外部エンティティ参照(XXE)の不適切な制限の脆弱性
https://jvn.jp/vu/JVNVU98062224/index.html

JVN#91715694 ShizenBox2における複数の脆弱性
https://jvn.jp/jp/JVN91715694/index.html

JVNVU#97909245 Hugging Face製Transformersにおけるユーザー同意確認前のリモートコード不正キャッシュの脆弱性
https://jvn.jp/vu/JVNVU97909245/index.html

JVNVU#90253159 CISA ICS Advisory / ICS Medical Advisory(2026年09月01日)
https://jvn.jp/vu/JVNVU90253159/index.html

2026年9月2日水曜日

2日 火曜日、先負

+ Google Chrome 152.0.7977.75/.76 released
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html

+ Mozilla Firefox 155.0 released
https://www.firefox.com/en-US/firefox/155.0/releasenotes/

+ Mozilla Foundation Security Advisory 2026-82 Security Vulnerabilities fixed in Firefox 155
https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/
CVE-2026-84117
CVE-2026-84118
CVE-2026-84119
CVE-2026-84120
CVE-2026-84121
CVE-2026-84122
CVE-2026-84123
CVE-2026-84124
CVE-2026-84125
CVE-2026-84126
CVE-2026-84127
CVE-2026-84128
CVE-2026-84129
CVE-2026-84130
CVE-2026-84131
CVE-2026-84132
CVE-2026-84133
CVE-2026-84134
CVE-2026-84135
CVE-2026-84136
CVE-2026-84137
CVE-2026-84138
CVE-2026-84139
CVE-2026-84140
CVE-2026-84141
CVE-2026-84142
CVE-2026-84143
CVE-2026-84144
CVE-2026-84145

+ Mozilla Foundation Security Advisory 2026-85 Security Vulnerabilities fixed in Firefox ESR 153.2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-85/

+ Mozilla Foundation Security Advisory 2026-84 Security Vulnerabilities fixed in Firefox ESR 140.15
https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/

+ Mozilla Foundation Security Advisory 2026-83 Security Vulnerabilities fixed in Firefox ESR 115.40
https://www.mozilla.org/en-US/security/advisories/mfsa2026-83/

+ Mozilla Foundation Security Advisory 2026-88 Security Vulnerabilities fixed in Thunderbird 153.2
https://www.mozilla.org/en-US/security/advisories/mfsa2026-88/

+ Mozilla Foundation Security Advisory 2026-87 Security Vulnerabilities fixed in Thunderbird 140.15
https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/

+ Mozilla Foundation Security Advisory 2026-86 Security Vulnerabilities fixed in Thunderbird 155
https://www.mozilla.org/en-US/security/advisories/mfsa2026-86/

VU#456290 Hugging Face Transformers library writes remote code to disk prior to consent check
https://www.kb.cert.org/vuls/id/456290

決算が暴くサイバー被害
被害企業の防止策 守りより「復旧力」へ [Part 4]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700004/?ST=nxt_thmit_security

決算が暴くサイバー被害
ランサム損失は28社 1年で倍の236億円に [Part 3]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700003/?ST=nxt_thmit_security

決算が暴くサイバー被害
18社が損失計上 海外拠点が標的に [Part 2]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700002/?ST=nxt_thmit_security

マルウエア徹底解剖
AIを取り巻くサイバー脅威を整理する [第81回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/081800082/?ST=nxt_thmit_security

データは語る
67%がSCS評価制度の取り組み進行 業務システムの共同利用は約9割
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/082700232/?ST=nxt_thmit_security

決算が暴くサイバー被害
「社長の声」装い詐取 不正アクセスなき詐欺 [Part 1]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/082700567/082700001/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIエージェント同士が「縄張り争い」、矛盾した指示によるリスク明らかに
https://xtech.nikkei.com/atcl/nxt/column/18/00676/082500232/?ST=nxt_thmit_security

2026年9月1日火曜日

1日 火曜日、友引

+ RHSA-2026:61766 Moderate: glib2 security update
https://access.redhat.com/errata/RHSA-2026:61766
CVE-2026-15588
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015

+ RHSA-2026:61257 Important: iperf3 security update
https://access.redhat.com/errata/RHSA-2026:61257
CVE-2026-71217

+ RHSA-2026:61248 Moderate: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:61248
CVE-2026-11979

+ RHSA-2026:61623 Moderate: gzip security update
https://access.redhat.com/errata/RHSA-2026:61623
CVE-2026-41991
CVE-2026-41992

+ RHSA-2026:61581 Moderate: tar security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2026:61581
CVE-2026-5704
CVE-2026-18477
CVE-2026-18508

+ RHSA-2026:61389 Important: iperf3 security update
https://access.redhat.com/errata/RHSA-2026:61389
CVE-2026-71217

+ RHSA-2026:61386 Important: nodejs:24 security update
https://access.redhat.com/errata/RHSA-2026:61386
CVE-2026-56846
CVE-2026-56848
CVE-2026-58043

+ RHSA-2026:61383 Important: nodejs:22 security update
https://access.redhat.com/errata/RHSA-2026:61383
CVE-2026-56846
CVE-2026-56848
CVE-2026-58043

+ RHSA-2026:61379 Important: freerdp security update
https://access.redhat.com/errata/RHSA-2026:61379
CVE-2026-55194
CVE-2026-67288
CVE-2026-67291
CVE-2026-67301

+ RHSA-2026:61355 Moderate: dbus-broker security update
https://access.redhat.com/errata/RHSA-2026:61355
CVE-2026-16730

+ RHSA-2026:61316 Important: xmlrpc-c security update
https://access.redhat.com/errata/RHSA-2026:61316
CVE-2026-15928

+ RHSA-2026:61247 Moderate: libxml2 security update
https://access.redhat.com/errata/RHSA-2026:61247
CVE-2026-6653
CVE-2026-11979

piyokangoの週刊システムトラブル
アイドル事務所VOISINGが利用するBIツールから個人情報流出、5万件公開か
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010900379/?ST=nxt_thmit_security

ニュース解説
SBOM国際ガイダンスで「最小要素」追加、企業の作成負担増も運用にメリット
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12005/?ST=nxt_thmit_security

ニュース解説
1200体のAIが「裏技」で情報共有、700体が攻撃に参加 OpenAIの侵入事案
https://xtech.nikkei.com/atcl/nxt/column/18/00001/12000/?ST=nxt_thmit_security

JVN#84094853 PALLET CONTROL製品におけるアクセス制御不備の脆弱性
https://jvn.jp/jp/JVN84094853/index.html

JVN#48718197 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)における反射型クロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN48718197/index.html

JVN#65118274 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)におけるオープンリダイレクトの脆弱性
https://jvn.jp/jp/JVN65118274/index.html

JVNVU#90210212 ヤマハ製VOCALOID6 Editorにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90210212/index.html

2026年8月31日月曜日

31日 月曜日、先勝

+ ■NSDの脆弱性情報が公開されました(CVE-2026-18664、CVE-2026-18916、CVE-2026-19401、CVE-2026-19538)
CVE-2026-18664
CVE-2026-18916
CVE-2026-19401
CVE-2026-19538

+ PHP 8.5.1, 8.4.25 released
https://www.php.net/ChangeLog-8.php#8.5.10
https://www.php.net/ChangeLog-8.php#8.4.25

JVN#42348352 GROWIにおける複数の脆弱性
https://jvn.jp/jp/JVN42348352/index.html

JVN#04485476 SOYシリーズにおける複数の脆弱性
https://jvn.jp/jp/JVN04485476/index.html

JVN#42011956 Zabbix agentにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN42011956/index.html

JVNVU#98375707 Siemens製品に対するアップデート(2026年8月)
https://jvn.jp/vu/JVNVU98375707/index.html

JVNVU#99593741 CISA ICS Advisory / ICS Medical Advisory(2026年08月27日)
https://jvn.jp/vu/JVNVU99593741/index.html

JVNVU#95523788 三菱電機数値制御装置におけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU95523788/index.html

JVNVU#96620683 三菱電機製FA製品のEthernet機能におけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU96620683/index.html

JVN#18593874 楽天Koboデスクトップアプリ(Windows版)のインストーラにおけるDLL読み込みに関する脆弱性
https://jvn.jp/jp/JVN18593874/index.html

月刊ランサムリポート
ランサムグループ「INC」の存在感が強まる Citrix Bleedを悪用して侵入
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/081800019/?ST=nxt_thmit_security

月刊ランサムリポート 第21回
急増するDeadLock被害、感染すると1対1のチャットにただちに誘導
https://xtech.nikkei.com/atcl/nxt/column/18/03053/082800022/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
ホテルからのM365が危ない 公衆Wi-Fi機器への侵害を警告
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/082600193/?ST=nxt_thmit_security

日経コンピュータ 大森敏行のプログラミングで行こう
大手AIベンダーで続々発生 AIの「暴走」は止められるか
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100112/082400145/?ST=nxt_thmit_security

ネットワーク機器利用実態調査2026
企業規模別のシェアが見える
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/081800254/081800001/?ST=nxt_thmit_security

NEWS close-up
狙われるGitHub
内部リポジトリー漏洩リスクは公開版の6倍に 「非公開だから安全」は危険な思い込み
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/081800336/?ST=nxt_thmit_security

中国テックジャイアント最前線 第67回
アリババのAIコーディングツール「Qoder」、組織力の強化も支援
https://xtech.nikkei.com/atcl/nxt/column/18/02653/082400083/?ST=nxt_thmit_security

ニュース解説
富士通がAI時代のサイバー防衛戦略、「減速防御」を掲げ年内にもサービス化
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11994/?ST=nxt_thmit_security