WordPress Tutor LMS プラグインの脆弱性 CVE-2026-78175 が FIX:Subscriber 権限での RCE の恐れ

Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability

2026/09/19 gbhackers — Wordfence Argus が発見したのは、WordPress 向け e ラーニングプラグイン Tutor LMS の脆弱性 CVE-2026-78175 (CVSS:8.8) であり、10 万以上の WordPress サイトが影響を受ける可能性があると警告している。この脆弱性は 2026年8月23日に、AI を活用する脆弱性調査エージェント Wordfence Argus により発見され、Wordfence Threat Intelligence チームにより検証された。

Continue reading “WordPress Tutor LMS プラグインの脆弱性 CVE-2026-78175 が FIX:Subscriber 権限での RCE の恐れ”

CISA KEV 警告 26/09/18:Linux Kernel の脆弱性 CVE-2025-39682/53266/39964 を登録

CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks

2026/09/19 CyberSecurityNews — 米国 Cybersecurity and Infrastructure Security Agency (CISA) が公表したのは、Linux Kernel に影響する 3 件の脆弱性であり、攻撃者による実環境での積極的な悪用を確認している。2026年9月18日に脆弱性 CVE-2025-39682/CVE-2026-53266/CVE-2025-39964 を Known Exploited Vulnerabilities (KEV) カタログに追加し、Binding Operational Directive 26-04 (BOD 26-04) に基づく修正期限を 9月21日に指定した。

Continue reading “CISA KEV 警告 26/09/18:Linux Kernel の脆弱性 CVE-2025-39682/53266/39964 を登録”