CISA Warns of Microsoft SharePoint Server Vulnerability Actively Exploited in Attacks
2026/07/15 CyberSecurityNews — Cybersecurity and Infrastructure Security Agency (CISA) は、Microsoft SharePoint Server に存在する重大な脆弱性 CVE-2026-56164 を、アクティブな悪用が確認されたことを理由に、Known Exploited Vulnerabilities (KEV) カタログに追加した。この欠陥は、Microsoft SharePoint Server のオンプレミス・デプロイメントに影響し、未認証の攻撃者に対して、リモートからの権限昇格を許すものである。
Tag: CVE-2026-56164
Microsoft 2026-07 月例アップデート:Critical 3 件を含む 570 件の脆弱性に対応
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
2026/07/14 BleepingComputer — 今日は Microsoft の July 2026 Patch Tuesday の日であり、攻撃で悪用された 2 件のゼロデイ脆弱性と、公開済みの 1 件を含む、570 件の欠陥に対するセキュリティ更新が提供された。今月の Patch Tuesday は、59 件の Critical 脆弱性に対処している。その内訳は、48 件がリモート・コード実行/9 件が権限昇格/1 件がセキュリティ・バイパス/1 件がスプーフィングとなっている。
Continue reading “Microsoft 2026-07 月例アップデート:Critical 3 件を含む 570 件の脆弱性に対応”