CISA KEV 警告 26/07/29:Cisco FMC の脆弱性 CVE-2026-20316 を登録

CISA Adds Cisco Secure Firewall Management Flaw to Exploited Vulnerabilities List

2026/07/30 gbhackers — U.S. Cybersecurity and Infrastructure Security Agency (CISA) は、Cisco の深刻な脆弱性 CVE-2026-20316 を Known Exploited Vulnerabilities (KEV) カタログに追加した。このアクティブに悪用されている脆弱性は、FMC:Firewall Management Center (以前の Firepower Management Center) に影響を及ぼす。この製品は、エンタープライズ環境内の Cisco ファイアウォール・デプロイメントを、設定/監視/管理するための集中型プラットフォームとして機能する。

Continue reading “CISA KEV 警告 26/07/29:Cisco FMC の脆弱性 CVE-2026-20316 を登録”

CISA KEV 警告 26/07/27:Fortinet FortiOS の脆弱性 CVE-2025-68686 を KEV に登録

CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks

2026/07/28 CyberSecurityNews — 米国 Cybersecurity and Infrastructure Security Agency (CISA) は、Fortinet FortiOS の脆弱性 CVE-2025-68686 が積極的に悪用されているとし、Known Exploited Vulnerabilities (KEV) カタログに追加した。この脆弱性は、FortiGate ファイアウォール及び他の Fortinet セキュリティ製品で使用されているオペレーティング・システム Fortinet FortiOS に影響を及ぼす。この脆弱性は、認可されていない脅威アクターに対して、機密性の高い情報が露出する問題として分類されており、CWE-200 にマッピングされている。

Continue reading “CISA KEV 警告 26/07/27:Fortinet FortiOS の脆弱性 CVE-2025-68686 を KEV に登録”

CISA KEV 警告 26/07/16:Fortinet FortiSandbox の脆弱性 CVE-2026-39808/25089 を KEV に登録

CISA Warns of Two Fortinet FortiSandbox Flaws Exploited to Execute Commands

2026/07/17 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Fortinet の FortiSandbox に存在する 2 件の深刻な脆弱性 CVE-2026-39808CVE-2026-25089 を、Known Exploited Vulnerabilities (KEV) カタログに追加した。これらの脆弱性は、OS コマンド・インジェクションの脆弱性 (CWE-78) に起因し、影響を受けるシステム上での不正なコマンド実行に悪用されている。影響が及ぶ製品の範囲は、FortiSandbox Cloud/FortiSandbox PaaS などの FortiSandbox の導入環境となる。

Continue reading “CISA KEV 警告 26/07/16:Fortinet FortiSandbox の脆弱性 CVE-2026-39808/25089 を KEV に登録”

CISA KEV 警告 26/07/15:Oracle E-Business の脆弱性 CVE-2026-46817 を KEV に登録

CISA Warns of Oracle E-Business Suite Vulnerability Actively Exploited in Attacks

2026/07/16 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Oracle E-Business Suite に存在する重大な脆弱性 CVE-2026-46817 を、Known Exploited Vulnerabilities (KEV) カタログに追加した。この欠陥は、Oracle E-Business Suite のコンポーネントである Oracle Payments に影響を及ぼす。この欠陥を突く未認証のリモート攻撃者が、ペイメント・サービスの制御を奪取する可能性がある。

Continue reading “CISA KEV 警告 26/07/15:Oracle E-Business の脆弱性 CVE-2026-46817 を KEV に登録”

CISA KEV 警告 26/07/14:SharePoint サーバの脆弱性 CVE-2026-56164 を KEV に登録

CISA Warns of Microsoft SharePoint Server Vulnerability Actively Exploited in Attacks

2026/07/15 CyberSecurityNews — Cybersecurity and Infrastructure Security Agency (CISA) は、Microsoft SharePoint Server に存在する重大な脆弱性 CVE-2026-56164 を、アクティブな悪用が確認されたことを理由に、Known Exploited Vulnerabilities (KEV) カタログに追加した。この欠陥は、Microsoft SharePoint Server のオンプレミス・デプロイメントに影響し、未認証の攻撃者に対して、リモートからの権限昇格を許すものである。

Continue reading “CISA KEV 警告 26/07/14:SharePoint サーバの脆弱性 CVE-2026-56164 を KEV に登録”

CISA KEV 警告 26/07/13:Cisco IOS の脆弱性 CVE-2008-4128 を KEV に登録

CISA Warns of Decades-Old Cisco IOS Vulnerability Actively Exploited in Attacks

2026/07/14 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Cisco IOS のバージョン 12.4(12)/12.4(4) に影響を及ぼす Cross-Site Request Forgery (CSRF) 脆弱性 CVE-2008-4128 を、2026年7月13日付けで Known Exploited Vulnerabilities Catalog に追加した。この脆弱性は、攻撃者によりアクティブに悪用されており、公開から何年も経過した後のレガシーなネットワーク・デバイスの欠陥が、セキュリティ・リスクをもたらすことを示している。

Continue reading “CISA KEV 警告 26/07/13:Cisco IOS の脆弱性 CVE-2008-4128 を KEV に登録”

CISA KEV 警告 26/07/10:Joomla エクステンション脆弱性 CVE-2026-48939/56291 を KEV に登録

CISA Warns of Joomla Sites Running iCagenda or Balbooa Exploited in Attacks

2026/07/13 CyberSecurityNews — Cybersecurity and Infrastructure Security Agency (CISA) は、Joomla エクステンションにおける高リスクの脆弱性 CVE-2026-48939CVE-2026-56291Known Exploited Vulnerabilities (KEV) カタログに追加した。これらの脆弱性は無制限のファイル・アップロードを可能にするものであり、この欠陥を突く攻撃者に対して、悪意のファイルのアップロードを許し、脆弱な Web サイトの乗っ取りを引き起こす可能性がある。

Continue reading “CISA KEV 警告 26/07/10:Joomla エクステンション脆弱性 CVE-2026-48939/56291 を KEV に登録”

CISA KEV 警告 26/07/07:Adobe ColdFusion の脆弱性 CVE-2026-48282 を KEV に登録

CISA orders feds to patch max severity ColdFusion flaw by Friday

2026/07/08 BleepingComputer — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Adobe ColdFusion 商用 Web アプリ開発プラットフォームに存在し、アクティブに悪用されている最高深刻度の欠陥について、7月10日 (金) までにパッチを適用するよう政府機関に命じた。この脆弱性 CVE-2026-48282 は、ColdFusion バージョン 2025.9/2023.20 以下に影響を及ぼす。また、リモートの脅威アクターが権限なしで、低複雑度の攻撃により悪用し、パッチ未適用のシステム上でコードを実行できる。

Continue reading “CISA KEV 警告 26/07/07:Adobe ColdFusion の脆弱性 CVE-2026-48282 を KEV に登録”

CISA KEV 警告 26/07/07:Langflow の脆弱性 CVE-2026-55255 を KEV に登録

CISA orders feds to prioritize patching Langflow auth bypass flaw

2026/07/08 BleepingComputer — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、AI エージェントを構築するためのビジュアル・フレームワークである Langflow に存在し、現在進行型で積極的に悪用されている脆弱性 CVE-2026-55255 を、7月7日付けで Known Exploited Vulnerabilities (KEV) カタログへ追加した。さらに、Binding Operational Directive (BOD) 26-04 に基づき、米国の Federal Civilian Executive Branch (FCEB) 機関に対して、7月10日までにデバイスを保護するよう命じた。

Continue reading “CISA KEV 警告 26/07/07:Langflow の脆弱性 CVE-2026-55255 を KEV に登録”

CISA KEV 警告 26/06/23:Ubiquiti UniFi OS/Lantronix の脆弱性を登録

CISA warns of max severity Ubiquiti flaws exploited in attacks

2026/06/24 BleepingComputer — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Ubiquiti の UniFi OS と Lantronix における脆弱性の積極的な悪用について警告を発した。BOD 26-04 指令に従い、連邦政府機関に求められるのは、ベンダーが提供するセキュリティ・アップデートまたは緩和策の 3日以内に適用することである。

Continue reading “CISA KEV 警告 26/06/23:Ubiquiti UniFi OS/Lantronix の脆弱性を登録”

CISA KEV 警告 26/06/18:Splunk Enterprise の脆弱性 CVE-2026-20253 を KEV に登録

CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks

2026/06/19 CyberSecurityNews — CISA は、Splunk Enterprise に存在する深刻な脆弱性が、実際の環境で積極的に悪用されているとして、組織に警告する高優先度アラートを発出した。この脆弱性 CVE-2026-20253 は、エンタープライズ環境に対する差し迫ったリスクを示しており、CISA の Known Exploited Vulnerabilities (KEV) カタログに追加された。

Continue reading “CISA KEV 警告 26/06/18:Splunk Enterprise の脆弱性 CVE-2026-20253 を KEV に登録”

CISA KEV 警告 26/06/12:Oracle PeopleSoft の脆弱性 CVE-2026-35273 を登録

CISA Issues Alert on Oracle PeopleSoft Vulnerability Exploited by Ransomware Groups

2026/06/17 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Oracle PeopleSoft Enterprise PeopleTools に存在する、深刻な脆弱性 CVE-2026-35273 (CWE-306) の積極的な悪用に関する緊急アラートを発出した。この脆弱性を悪用する未認証の攻撃者は、脆弱な PeopleSoft 環境の完全な制御を可能にする。

Continue reading “CISA KEV 警告 26/06/12:Oracle PeopleSoft の脆弱性 CVE-2026-35273 を登録”

CISA KEV 警告 26/06/15:Cisco SD-WAN と LiteSpeed cPanel プラグインの脆弱性を KEV に登録

U.S. CISA adds Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog

2026/06/16 SecurityAffairs — 米国 Cybersecurity and Infrastructure Security Agency (CISA) が、Cisco Catalyst および LiteSpeed cPanel プラグインの脆弱性を、Known Exploited Vulnerabilities (KEV) カタログに登録した。今回、カタログに追加された 2 件の脆弱性は、以下のとおりである。

  • CVE-2026-20262 (CVSS 6.5):Cisco Catalyst SD-WAN Manager のディレクトリまたはパス・トラバーサルの脆弱性
  • CVE-2026-54420 (CVSS 8.5):LiteSpeed cPanel Plugin の UNIX シンボリック・リンク (Symlink) 追跡の脆弱性
Continue reading “CISA KEV 警告 26/06/15:Cisco SD-WAN と LiteSpeed cPanel プラグインの脆弱性を KEV に登録”

CISA KEV 警告 26/06/09:Google Chromium の脆弱性 CVE-2026-11645 を登録

CISA Issues Alert on Actively Exploited Google Chromium Zero-Day Flaw

2026/06/10 gbhackers — 米国 Cybersecurity and Infrastructure Security Agency (CISA) は、悪意の Web コンテンツを通じて任意のコード実行を可能にする、Google Chromium のゼロデイ脆弱性 CVE-2026-11645 について警告を発出した。この脆弱性は Chromium の V8 JavaScript エンジンに影響する境界外読み取りおよび書き込みの問題を含むものであり、CWE-787/CWE-125 に分類される。細工された HTML ページを、ユーザーが閲覧する際にトリガーされる欠陥であり、リモートの攻撃者に対して、ブラウザのサンドボックス内での任意のコード実行を許す可能性がある。

Continue reading “CISA KEV 警告 26/06/09:Google Chromium の脆弱性 CVE-2026-11645 を登録”

CISA KEV 警告 26/06/05:SolarWinds Serv-U の脆弱性 CVE-2026-28318 を追加

CISA Alerts on Actively Exploited SolarWinds Serv-U Denial-of-Service Flaw

2026/06/06 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、SolarWinds の Serv-U に存在する深刻な脆弱性を Known Exploited Vulnerabilities (KEV) カタログに正式に追加した。この脆弱性 CVE-2026-28318 を悪用する未認証のリモート攻撃者は、ファイル転送サービスをクラッシュさせることが可能である。すでに、実環境で悪用が確認されており、インターネットに公開された Serv-U インスタンスを運用する企業ネットワークに深刻なリスクが生じている。

Continue reading “CISA KEV 警告 26/06/05:SolarWinds Serv-U の脆弱性 CVE-2026-28318 を追加”

CISA KEV 警告 26/06/02:Linux Kernel の脆弱性 CVE-2022-0492 を登録

CISA Issues Alert on Actively Exploited Linux Kernel Security Flaw

2026/06/05 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Linux カーネルの脆弱性 CVE-2022-0492 が実環境で積極的に悪用されているとして、Known Exploited Vulnerabilities (KEV) カタログに登録した。この脆弱性は、不適切な認証の問題として分類されるものであり、cgroups v1 の release_agent 機能を使用する Linux システムに影響し、侵害した環境内での権限昇格を許す。

Continue reading “CISA KEV 警告 26/06/02:Linux Kernel の脆弱性 CVE-2022-0492 を登録”

CISA KEV 警告 26/05/29:Palo Alto PAN-OS の脆弱性 CVE-2026-0257 を追加

Palo Alto PAN-OS Authentication Bypass Vulnerability Actively Exploited in the Wild

2026/05/30 gbhackers — Palo Alto Networks の PAN-OS および Prisma Access に影響する認証バイパスの深刻な脆弱性が、現実の攻撃において活発に悪用されている。この状況を受け、2026年5月29日に米国の Cybersecurity and Infrastructure Security Agency (CISA) が、脆弱性 CVE-2026-0257 を Known Exploited Vulnerabilities (KEV) カタログに追加した。 

Continue reading “CISA KEV 警告 26/05/29:Palo Alto PAN-OS の脆弱性 CVE-2026-0257 を追加”

CISA KEV 警告 26/05/26:LiteSpeed cPanel プラグインの脆弱性 CVE-2026-48172 を登録

CISA Warns LiteSpeed cPanel Plugin Vulnerability Is Being Exploited in Attacks

2026/05/27 gbhackers — CISA は、LiteSpeed cPanel プラグインに存在する深刻な脆弱性を Known Exploited Vulnerabilities (KEV) カタログに追加し、実環境におけるアクティブな悪用について緊急警告を発した。この脆弱性 CVE-2026-48172 は、深刻な権限昇格リスクをもたらすものであり、影響を受けるサーバの完全な制御を、攻撃者に許す可能性がある。特に、複数ユーザーの cPanel アカウントが共有される、ホスティング環境での危険性が極めて高い。

Continue reading “CISA KEV 警告 26/05/26:LiteSpeed cPanel プラグインの脆弱性 CVE-2026-48172 を登録”

CISA KEV 警告 26/05/20:Defender の脆弱性 CVE-2026-45498/41091 を KEV に登録

CISA Issues Alert on Exploited Microsoft Defender Zero-Day Vulnerabilities

2026/05/22 gbhackers — 米国の CISA は、Microsoft Defender に影響を与える 2件のゼロデイ脆弱性に対処するよう、連邦政府の組織に対して指令を発出した。これらの脆弱性は、2026年5月20日に Known Exploited Vulnerabilities (KEV) カタログへ追加された。

Continue reading “CISA KEV 警告 26/05/20:Defender の脆弱性 CVE-2026-45498/41091 を KEV に登録”

CISA KEV 警告 26/05/21:Langflow の脆弱性 CVE-2025-34291 を KEV に登録

CISA Adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog

2026/05/22 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Langflow の深刻な脆弱性 CVE-2025-34291 を Known Exploited Vulnerabilities (KEV) カタログに追加し、実環境での悪用リスクを強調するとともに即時対応を求めている。この脆弱性は、AI 駆動ワークフローの構築とオーケストレーションに使用される、Langflow のオリジン検証の欠陥に起因する。

Continue reading “CISA KEV 警告 26/05/21:Langflow の脆弱性 CVE-2025-34291 を KEV に登録”

CISA KEV 警告 26/05/21:Trend Micro Apex One の脆弱性 CVE-2026-34926 を KEV に登録

CISA Warns Trend Micro Apex One Vulnerability Is Being Exploited in Attacks

2026/05/22 gbhackers — CISA は、新たに公開された Trend Micro Apex One の脆弱性を Known Exploited Vulnerabilities (KEV) カタログに登録し、この欠陥が実環境で積極的に悪用されていると警告した。この脆弱性 CVE-2026-34926 が影響を及ぼす範囲は、Trend Micro Apex One のオンプレミス・デプロイメントであり、エンタープライズ環境に深刻なリスクをもたらす。

Continue reading “CISA KEV 警告 26/05/21:Trend Micro Apex One の脆弱性 CVE-2026-34926 を KEV に登録”

Cisco Catalyst SD-WAN の脆弱性 CVE-2026-20182 が FIX:Admin 奪取の可能性

Cisco Catalyst SD-WAN Controller 0-Day Actively Exploited to Gain Admin Access

2026/05/15 CyberSecurityNews — Cisco Catalyst SD-WAN Controller における、脆弱性 CVE-2026-20182 (CVSS:10.0:Critical) が積極的に悪用されている。この脆弱性を悪用する未認証のリモート攻撃者は、認証を完全にバイパスし、エンタープライズ・ネットワーク基盤の管理権限を掌握できる状態にある。この脆弱性により、オンプレミス/クラウド/政府環境を含む SD-WAN 展開全体が重大なリスクにさらされている。

Continue reading “Cisco Catalyst SD-WAN の脆弱性 CVE-2026-20182 が FIX:Admin 奪取の可能性”

CISA KEV 警告 26/05/06:Palo Alto PAN-OS の脆弱性 CVE-2026-0300 を KEV に登録

CISA Issues Warning Over Palo Alto PAN-OS Flaw Enabling Root-Level Access

2026/05/07 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Palo Alto Networks の PAN-OS に存在する深刻な脆弱性 CVE-2026-0300 について緊急警告を発出し、2026年5月6日に KEV (Known Exploited Vulnerabilities) カタログに追加した。この脆弱性を悪用する未認証ユーザーは、完全なシステム制御を可能にするため、連邦機関には 2026年5月9日までの対策の完了が指示されている。

Continue reading “CISA KEV 警告 26/05/06:Palo Alto PAN-OS の脆弱性 CVE-2026-0300 を KEV に登録”

CISA KEV 警告 26/05/01:Linux Kernel の脆弱性 “Copy Fail” CVE-2026-31431 を KEV に登録

CISA Warns of Linux “Copy Fail” 0-Day Vulnerability Exploited to Root Systems

2026/05/04 CyberSecurityNews — 米国の CISA は、Linux カーネルの深刻なゼロデイ脆弱性を Known Exploited Vulnerabilities (KEV) カタログに追加し、連邦機関および世界中の組織に対して、即時のパッチ適用もしくは影響を受けるシステムの使用停止を求めた。Copy Fail と呼ばれる脆弱性 CVE-2026-31431 (CVSS:7.8:High) は、CWE-699 (Incorrect Resource Transfer Between Spheres) に分類される。

Continue reading “CISA KEV 警告 26/05/01:Linux Kernel の脆弱性 “Copy Fail” CVE-2026-31431 を KEV に登録”

CISA KEV の修正期間が 3 日に短縮? Anthropic Mythos などの登場が脆弱性への対応を変化させる

U.S. Officials Consider Three-Day Patch Rule in Wake of Anthropic’s Mythos

2026/05/04 SecurityBoulevard — Anthropic の Mythos および OpenAI の GPT-5.4-Cyber といった先端 AI モデルの登場を受け、政府当局が関連機関に課している重大な脆弱性の修正期限について、大幅な短縮を検討していると報じられている。これらの AI モデルは、ソフトウェア脆弱性の検出だけではなく悪用にも優れている。

Continue reading “CISA KEV の修正期間が 3 日に短縮? Anthropic Mythos などの登場が脆弱性への対応を変化させる”

CISA KEV 警告 26/04/30:cPanel & WHM/WP Squared の脆弱性 CVE-2026-41940 を登録

CISA Alert Highlights Active Exploitation of cPanel & WHM Security Bug

2026/05/04 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、WebPros の cPanel & WebHost Manager (WHM) および WordPress Squared (WP2) に影響を及ぼす、深刻なセキュリティ脆弱性 CVE-2026-41940 (CVSS:9.8) について警告を発した。2026年4月30日に CISA は、この脆弱性を Known Exploited Vulnerabilities (KEV) カタログに正式に追加し、実環境の攻撃で積極的に悪用されていることを確認した。

Continue reading “CISA KEV 警告 26/04/30:cPanel & WHM/WP Squared の脆弱性 CVE-2026-41940 を登録”

CISA KEV 警告 26/04/28:ScreenConnect の脆弱性 CVE-2024-1708 を登録

CISA Warns of ConnectWise ScreenConnect Flaw Exploited in Attacks

2026/04/29 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) が、ConnectWise ScreenConnect に存在する深刻なセキュリティ欠陥について緊急警告を発出した。すでに実環境の攻撃で悪用が確認されている、深刻な脆弱性 CVE-2024-1708 について報告を受けた CISA が、2026年4月28日付けで Known Exploited Vulnerabilities (KEV) カタログに追加した。この警告は、政府機関および民間組織のネットワークに対して、速やかなセキュリティ対策を促す重大なものである。

Continue reading “CISA KEV 警告 26/04/28:ScreenConnect の脆弱性 CVE-2024-1708 を登録”

CISA KEV 警告 26/04/24: SimpleHelp/Samsung/D-Link の脆弱性を登録

U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog

2026/04/25 SecurityAffairs — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、SimpleHelp/Samsung/D-Link に関する脆弱性を Known Exploited Vulnerabilities (KEV) カタログへ追加した。以下は追加された脆弱性である:

Continue reading “CISA KEV 警告 26/04/24: SimpleHelp/Samsung/D-Link の脆弱性を登録”

CISA KEV 警告 26/04/20:Cisco Catalyst SD-WAN Manager の脆弱性 CVE-2026-20122/20128/20133 を登録

CISA Alerts Defenders to Exploited Cisco Catalyst SD-WAN Manager Security Flaws

2026/04/21 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Cisco Catalyst SD-WAN Manager の脆弱性が積極的に悪用されている状況を踏まえ、ネットワーク防御担当者に対して緊急の警告を発出した。2026年4月20日に CISA は、このプラットフォームに影響を与える 3 種類のセキュリティ脆弱性を Known Exploited Vulnerabilities (KEV) カタログに正式に追加した。

Continue reading “CISA KEV 警告 26/04/20:Cisco Catalyst SD-WAN Manager の脆弱性 CVE-2026-20122/20128/20133 を登録”

CISA KEV 警告 26/04/16:ActiveMQ の脆弱性 CVE-2026-34197 を KEV に登録

CISA Warns of Apache ActiveMQ Input Validation Vulnerability Exploited in Attacks

2026/04/17 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Apache ActiveMQ に存在する Critical なセキュリティ欠陥に対して緊急警告を発出した。2026年04月16日に同機関は、脆弱性 CVE-2026-34197 を Known Exploited Vulnerabilities (KEV) カタログへ正式に登録した。

Continue reading “CISA KEV 警告 26/04/16:ActiveMQ の脆弱性 CVE-2026-34197 を KEV に登録”

CISA KEV 警告 26/04/13:Adobe/Microsoft/Fortinet の脆弱性 7件を登録

U.S. CISA adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

2026/04/14 SecurityAffairs — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Adobe/Microsoft/Fortinet の脆弱性を Known Exploited Vulnerabilities (KEV)カタログへ登録した。以下は、今回カタログへ追加された脆弱性である。

CVE-2026-34621:Adobe Acrobat/Reader Prototype Pollution 脆弱性
CVE-2012-1854:Visual Basic for Applications 不正ライブラリロード脆弱性
CVE-2020-9715:Adobe Acrobat Use-After-Free 脆弱性
CVE-2023-21529:Exchange Server 信頼できないデータのデシリアライズ脆弱性
CVE-2023-36424:Windows 境界外読み取り脆弱性
CVE-2025-60710:Windows リンクフォロー脆弱性
CVE-2026-21643:Fortinet SQL Injection 脆弱性

Continue reading “CISA KEV 警告 26/04/13:Adobe/Microsoft/Fortinet の脆弱性 7件を登録”

CISA KEV 警告 26/04/06:FortiClient EMS の脆弱性 CVE-2026-35616 を KEV に登録

CISA Warns of Fortinet 0-Day Vulnerability Actively Exploited in Attacks

2026/04/06 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Fortinet FortiClient Enterprise Management Server (EMS) に存在する深刻なアクセス制御の脆弱性 CVE-2026-35616 を、Known Exploited Vulnerabilities (KEV) カタログに登録した。この脆弱性の追加は2026年04月06日に行われ、2026年04月09日までの対応が連邦機関に義務付けられた。

Continue reading “CISA KEV 警告 26/04/06:FortiClient EMS の脆弱性 CVE-2026-35616 を KEV に登録”

CISA KEV 警告 26/04/02:TrueConf の脆弱性 CVE-2026-3502 を登録

CISA Adds TrueConf Vulnerability to KEV Catalog Following Active Exploitation

2026/04/06 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、TrueConf の深刻な脆弱性を Known Exploited Vulnerabilities (KEV) カタログへ正式に追加した。この脆弱性 CVE-2026-3502 は、実環境においてアクティブに悪用されているため、ネットワーク保護のための速やかな対応が、連邦機関および民間組織に求められる。

Continue reading “CISA KEV 警告 26/04/02:TrueConf の脆弱性 CVE-2026-3502 を登録”

CISA KEV 警告 26/03/30:Citrix NetScaler の脆弱性 CVE-2026-3055 を登録

CISA Warns of Citrix NetScaler Vulnerability Actively Exploited in Attacks

2026/03/31 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Citrix NetScaler 製品に影響する深刻な脆弱性について緊急の警告を発出した。この脆弱性 CVE-2026-3055 は、実環境におけるアクティブな悪用が確認されたことを受け、CISA の Known Exploited Vulnerabilities (KEV) カタログへ正式に追加された。

Continue reading “CISA KEV 警告 26/03/30:Citrix NetScaler の脆弱性 CVE-2026-3055 を登録”

CISA KEV 警告 26/03/27:F5 BIG-IP の脆弱性 CVE-2025-53521 を登録

CISA Warns of F5 BIG-IP Vulnerability Actively Exploited in Attacks

2026/03/28 CyberSecurityNews — 米国 Cybersecurity and Infrastructure Security Agency (CISA) が公表したのは、F5 BIG-IP システムに影響を及ぼす脆弱性の Known Exploited Vulnerabilities (KEV) カタログへの登録である。この脆弱性 CVE-2025-53521 は、2026年3月27日に正式に登録され、連邦機関に対して 2026年3月30日までの対応期限が設定された。

Continue reading “CISA KEV 警告 26/03/27:F5 BIG-IP の脆弱性 CVE-2025-53521 を登録”

CISA KEV 警告 26/03/26:Trivy Scanner の脆弱性 CVE-2026-33634 を登録

CISA Adds Critical Aquasecurity Trivy Scanner Vulnerability to KEV Catalog

2026/03/27 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Aqua Security の Trivy スキャナに影響を及ぼす深刻な脆弱性 CVE-2026-33634 を、Known Exploited Vulnerabilities (KEV) カタログへ緊急追加した。この脆弱性は、CI/CD (Continuous Integration/Continuous Deployment) 環境を標的とする埋め込み型 (エンベッド型) のマルウェア・コードに関係するものだ。

Continue reading “CISA KEV 警告 26/03/26:Trivy Scanner の脆弱性 CVE-2026-33634 を登録”

CISA KEV 警告 26/03/25:Langflow のコード・インジェクションの脆弱性 CVE-2026-33017 を登録

CISA Warns of Langflow Code Injection Vulnerability Exploited in Attacks

2026/03/26 CyberSecurityNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は 2026年3月25日に、Langflow に影響を及ぼす深刻な脆弱性を Known Exploited Vulnerabilities (KEV) カタログへ正式に追加した。この脆弱性 CVE-2026-33017 は、実環境において積極的な悪用が確認されている、きわめて危険なコード・インジェクションの欠陥である。

Continue reading “CISA KEV 警告 26/03/25:Langflow のコード・インジェクションの脆弱性 CVE-2026-33017 を登録”

CISA KEV 警告 26/03/20:Apple/Craft CMS/Laravel Livewire の脆弱性を登録

U.S. CISA adds Apple, Laravel Livewire and Craft CMS flaws to its Known Exploited Vulnerabilities catalog

2026/03/22 SecurityAffairs — 米国 Cybersecurity and Infrastructure Security Agency (CISA) は、Apple/Laravel Livewire/Craft CMS に存在する複数の脆弱性を Known Exploited Vulnerabilities (KEV) カタログへ追加した。追加された脆弱性は、以下の通りである。

  • CVE-2025-31277 (CVSS:8.8):Apple のバッファ・オーバーフロー
  • CVE-2025-43510 (CVSS:7.8):Apple の不適切なロック
  • CVE-2025-43520 (CVSS:8.8):Apple のバッファ・オーバーフロー
  • CVE-2025-32432 (CVSS:10.0):Craft CMS のコード・インジェクション
  • CVE-2025-54068 (CVSS:9.8):Laravel Livewire のコード・インジェクション
Continue reading “CISA KEV 警告 26/03/20:Apple/Craft CMS/Laravel Livewire の脆弱性を登録”

CISA KEV 警告 26/03/18:Zimbra Collaboration の脆弱性 CVE-2025-66376 を登録

CISA Adds Exploited Zimbra Collaboration Suite Flaw to Warning List

2026/03/19 gbhackers — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Zimbra Collaboration Suite (ZCS) に影響を及ぼす深刻な脆弱性 CVE-2025-66376 を Known Exploited Vulnerabilities (KEV) カタログへ正式に追加した。このプラットフォームを使用する連邦政府の機関/組織は、2026年4月1日までに必要なアップデートを適用し、積極的な攻撃によるリスクを軽減する必要がある。

Continue reading “CISA KEV 警告 26/03/18:Zimbra Collaboration の脆弱性 CVE-2025-66376 を登録”

CISA KEV 警告 26/03/18:Microsoft SharePoint の脆弱性 CVE-2026-20963 を登録

CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks

2026/03/19 CyberSecurityNews — Microsoft SharePoint における深刻なセキュリティ脆弱性 CVE-2026-20963 が、現在進行形で積極的に悪用されている。2026年3月18日の時点で CISA は、この脆弱性を Known Exploited Vulnerabilities (KEV) カタログに正式に追加した。今回の KEV への追加により、連邦政府機関へのネットワーク攻撃においても、この脆弱性が悪用されていることが確認された。

Continue reading “CISA KEV 警告 26/03/18:Microsoft SharePoint の脆弱性 CVE-2026-20963 を登録”

CISA KEV 警告 26/03/13:Google Skia/V8 JavaScript の脆弱性 CVE-2026-3909/3910 を登録

CISA Alerts Users to Exploited Chrome 0-Day Flaws

2026/03/17 gbhackers — 米国 Cybersecurity and Infrastructure Security Agency (CISA) は、きわめて深刻なゼロデイ脆弱性 CVE-2026-3909/CVE-2026-3910 について緊急警告を発表した。これらの脆弱性は、Google Chrome と基盤技術に影響を与え、実環境において現在進行形で悪用されている。そのため CISA は、2 件の脆弱性を Known Exploited Vulnerabilities (KEV) カタログに追加し、連邦機関に対して即時パッチ適用を義務付けるとともに、民間組織にも同様の対応を強く推奨している。

Continue reading “CISA KEV 警告 26/03/13:Google Skia/V8 JavaScript の脆弱性 CVE-2026-3909/3910 を登録”

CISA KEV 警告 26/03/16:Wing FTP Server の脆弱性 CVE-2025-47813 を登録

U.S. CISA adds a flaw in Wing FTP Server to its Known Exploited Vulnerabilities catalog

2026/03/16 SecurityAffairs — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Wing FTP Server の脆弱性 CVE-2025-47813 (CVSS:4.3) を Known Exploited Vulnerabilities (KEV) カタログへ追加した。この脆弱性 CVE-2025-47813 は、Wing FTP Server バージョン 7.4.4 未満に影響を及ぼす情報漏洩の欠陥である。この問題は、Web 認証プロセス中の “loginok.html” ページで発生する。

Continue reading “CISA KEV 警告 26/03/16:Wing FTP Server の脆弱性 CVE-2025-47813 を登録”

CISA KEV 警告 26/03/09:SolarWinds Web Help Desk の脆弱性 CVE-2025-26399 を KEV カタログへ登録

SolarWinds Web Help Desk Deserialization Vulnerability Enables Command Execution

2026/03/12 CyberSecurityNews — SolarWinds Web Help Desk に存在する深刻なセキュリティ脆弱性について、サイバーセキュリティ当局は警告を発し、システム管理者に対して直ちに対応するよう呼びかけている。脆弱性 CVE-2025-26399 を悪用する攻撃者は、ホスト・マシン上で不正なコマンドを直接実行する可能性を得る。この脆弱性は、連邦政府機関内での悪用が確認されていることから、米国 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) カタログに正式に追加した。

Continue reading “CISA KEV 警告 26/03/09:SolarWinds Web Help Desk の脆弱性 CVE-2025-26399 を KEV カタログへ登録”

CISA KEV 警告 26/03/05:Apple macOS/iOS などにおける複数の脆弱性を登録

CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks

2026/03/09 CyberSecurityNews — 2026年3月5日に CISA は、macOS/iOS/iPadOS などの Apple 製品に影響する 3 件の脆弱性Known Exploited Vulnerabilities (KEV) カタログに追加した。この追加は、脅威アクターが実環境でこれらの欠陥を悪用していることを示すものであり、ネットワーク防御担当者に対する警告である。サイバー・リスクを管理する組織にとっては、即時のパッチ適用が最優先事項となる。

Continue reading “CISA KEV 警告 26/03/05:Apple macOS/iOS などにおける複数の脆弱性を登録”

BeyondTrust の脆弱性 CVE-2026-1731:VShell/SparkRAT 展開キャンペーンを分析

Hackers Exploit Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT

2026/02/20 gbhackers — BeyondTrust の Remote Support ソフトウェアに存在する深刻な脆弱性を、脅威アクターたちが積極的に悪用している。この脆弱性を悪用する攻撃者は、VShell バックドアおよび SparkRAT を展開し、公開されているシステムを完全に侵害している。この脆弱性 CVE-2026-1731 は、米国/欧州/アジア太平洋地域の複数業界に対する攻撃で実際に悪用されている。

Continue reading “BeyondTrust の脆弱性 CVE-2026-1731:VShell/SparkRAT 展開キャンペーンを分析”

CISA KEV 警告 26/02/18:Dell RecoverPoint と GitLab の脆弱性を登録

U.S. CISA adds Dell RecoverPoint and GitLab flaws to its Known Exploited Vulnerabilities catalog

2026/02/19 SecurityAffairs — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Dell RecoverPoint および GitLab の脆弱性を Known Exploited Vulnerabilities (KEV) カタログに追加した。追加された脆弱性は以下の通りである。

  • CVE-2021-22175 (CVSS:6.8):GitLab Server の SSRF の脆弱性
  • CVE-2026-22769 (CVSS:10.0):Dell RecoverPoint 認証情報ハードコード
Continue reading “CISA KEV 警告 26/02/18:Dell RecoverPoint と GitLab の脆弱性を登録”

CISA KEV 警告 26/02/17:Chrome/ThreatSonar/Zimbra/Windows の脆弱性を登録

CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update

2026/02/18 TheHackerNews — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、実環境におけるアクティブな悪用の証拠を根拠として、Known Exploited Vulnerabilities (KEV) カタログに 4 件のセキュリティ欠陥を追加した。 それらの脆弱性は、Google Chrome/TeamT5 ThreatSonar Anti-Ransomware/Synacor Zimbra Collaboration Suite/Microsoft Windows Video ActiveX Control に存在するものだ。

Continue reading “CISA KEV 警告 26/02/17:Chrome/ThreatSonar/Zimbra/Windows の脆弱性を登録”

CISA KEV 警告 26/02/13:BeyondTrust RS/PRA の脆弱性 CVE-2026-1731 を登録

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

2026/02/14 SecurityAffairs — 米国 Cybersecurity and Infrastructure Security Agency (CISA) は、BeyondTrust Remote Support (RS)/Privileged Remote Access (PRA) に影響する脆弱性 CVE-2026-1731 (CVSS:9.9)Known Exploited Vulnerabilities (KEV) カタログへ追加した。2026年2月6日に BeyondTrust が公開したのは、RS および旧バージョンの PRA 製品に存在する深刻な欠陥に対処するセキュリティ更新プログラムである。この脆弱性を悪用する未認証の攻撃者は、特別に細工したリクエストを送信することで、リモートから OS コマンドを実行する可能性がある

Continue reading “CISA KEV 警告 26/02/13:BeyondTrust RS/PRA の脆弱性 CVE-2026-1731 を登録”

CISA KEV 警告 26/02/12:SolarWinds WHD/Notepad++/Microsoft Config Man/Apple の脆弱性を登録

U.S. CISA adds SolarWinds Web Help Desk, Notepad++, Microsoft Configuration Manager, and Apple devices flaws to its Known Exploited Vulnerabilities catalog

2026/02/13 SecurityAffairs — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、SolarWinds Web Help Desk/Notepad++/Microsoft Configuration Manager/Apple デバイスに関する脆弱性を、Known Exploited Vulnerabilities (KEV) カタログに追加した。追加された脆弱性は、以下の通りである。

  • CVE-2024-43468 (CVSS:9.8):Microsoft Config Manager の SQLi 欠陥
  • CVE-2025-15556 (CVSS:7.7):Notepad++ のアップデート整合性欠如
  • CVE-2025-40536 (CVSS:8.1):SolarWinds WHD のセキュリティ制御バイパス
  • CVE-2026-20700 (CVSS:7.8):Apple のバッファ・オーバーフロー
Continue reading “CISA KEV 警告 26/02/12:SolarWinds WHD/Notepad++/Microsoft Config Man/Apple の脆弱性を登録”

CISA KEV 警告 26/02/10:Microsoft Office/Windows の複数の脆弱性を登録

U.S. CISA adds Microsoft Office and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog

2026/02/11 SecurityAffairs — 米国の Cybersecurity and Infrastructure Security Agency (CISA) は、Microsoft Office および Microsoft Windows の脆弱性を Known Exploited Vulnerabilities (KEV) カタログに追加した。今回カタログに追加された脆弱性は、いずれも February 2026 Patch Tuesday でゼロデイとして公開されたものである。

Continue reading “CISA KEV 警告 26/02/10:Microsoft Office/Windows の複数の脆弱性を登録”