セキュリティ情報ポータル
当サイトが扱っているのは個別のCVEと、その環境別の対応です。実務ではそれだけでは足りないことがあります。「この製品の月例更新がまとめて出た」「この事案はどういう経緯で収束したのか」といった、CVE 単位では表せない情報です。
そこは各媒体の仕事なので、当サイトは案内だけします。ここに並ぶのは見出しと日付と元記事へのリンクで、本文は転載していません。画像は配信元が公開している OGP 画像を参照しているだけで、当サイトに複製していません。読むときは必ず元記事へ移動してください。
情報源: JVN / Security NEXT / BleepingComputer / The Hacker News / ScanNetSecurity / JPCERT/CC / IPA 重要なセキュリティ情報 / piyolog / CISA Advisories / Cisco Talos Blog。最終更新 2026/09/30(400件)。脆弱性の対応に関わる記事だけを選んで載せています(漏えい・詐欺など対応表と関係のない話題は外しています)。
公的機関・ベンダーの注意喚起131件
- PFU製Image Scanner Driver for Linuxにおける複数の脆弱性 株式会社PFUが提供するImage Scanner Driver for Linuxには、複数の脆弱性が存在します。
- Pgpool-IIにおける複数の脆弱性 Pgpool Global Development Groupが提供するPgpool-IIには、複数の脆弱性が存在します。
- Authlibライブラリにおける署名検証が回避される脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- バッファロー製Wi-Fi製品における複数の脆弱性 株式会社バッファローが提供する複数のWi-Fi製品の設定画面には、複数の脆弱性が存在します。
- Androidアプリ「Readwise Reader」における複数のクロスサイトスクリプティングの脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway <p>CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citr
- CISA Adds Two Known Exploited Vulnerabilities to Catalog <p class="text-align-justify">CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov
- baserCMS用プラグイン「アドオンマイグレーター」 における信頼できない制御領域からの機能の組み込みに関する脆弱性 baserCMSユーザー会が提供するbaserCMS用プラグイン「アドオンマイグレーター」 には、信頼できない制御領域からの機能の組み込みに関する脆弱性が存在します。
- baserCMSにおける複数の脆弱性 baserCMSユーザー会が提供するbaserCMSには複数の脆弱性が存在します。
- CISA Adds Two Known Exploited Vulnerabilities to Catalog <p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities
- CISA Adds One Known Exploited Vulnerability to Catalog <p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-c
- ViewSonic vCastにおける複数の脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- Norwegian Cruise Lineのドアアクセスコントローラにおける認証不備の脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- CISA ICS Advisory / ICS Medical Advisory(2026年09月24日) 米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。
- 三菱電機製GX Works3およびモーション制御設定における認証回避の脆弱性 三菱電機株式会社が提供するGX Works3およびモーション制御設定のブロックパスワード設定機能には、認証回避の脆弱性が存在します。
- Apache Tomcatにおける複数の脆弱性(2026年9月23日) The Apache Software Foundationから、Apache Tomcatの15件の脆弱性に対してアドバイザリが公開されました。
- Imprivata製Enterprise Access ManagementにおけるRSA鍵ペアを更新できない脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- Cinnamon AI製Kotaemonのマルチユーザーチャットハンドラにおける不適切な認可の脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- ベンダによる署名済みUEFIアプリケーションにおけるセキュアブートバイパスの脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- CISA ICS Advisory / ICS Medical Advisory(2026年09月22日) 米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。
- Eufy Omni C20, Omni X10 Pro <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-02.json"><strong
- Botslab G980H Dashcams <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-267-01.json"><strong
- Siemens Mendix Runtime (Update A) <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-209-02.json"><strong
- CISA Adds Two Known Exploited Vulnerabilities to Catalog <p> CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabi
- Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators <h2><strong>Introduction</strong></h2> <p>The Federal Bureau of Investigation (FBI) and Cybersecurity and Infr
- Siemens Industrial Edge Management <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-06.json"><strong
- OpenPLC Runtime v3 <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-09.json"><strong
- CISA Adds Four Known Exploited Vulnerabilities to Catalog <p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilitie
- lwIP (Lightweight IP) <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-02.json"><strong
- Siemens WTV676 and WTV776 <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-08.json"><strong
- Siemens SIPLUS and SIMATIC Products <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-04.json"><strong
- Siemens Desigo CC family <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-05.json"><strong
- Siemens SIMOVE Fleetmanager and SIPLANT <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-07.json"><strong
- Siemens Siveillance Control <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-03.json"><strong
- lwIP TCP/IP Stack MQTT Client Application <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-265-01.json"><strong
- CISA Adds One Known Exploited Vulnerability to Catalog <p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-c
- ISC BINDにおける複数の脆弱性(2026年9月) ISC(Internet Systems Consortium)から、ISC BINDの複数の脆弱性が公開されました。
- CISA Adds Two Known Exploited Vulnerabilities to Catalog <p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities
- CISA Adds One Known Exploited Vulnerability to Catalog <p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-c
- CISA ICS Advisory / ICS Medical Advisory(2026年09月17日) 米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。
- DokployにおけるOSコマンドインジェクションの脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-07.json"><strong
- Mitsubishi Electric GX Works3 and Motion Control Settings <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-02.json"><strong
- Hitachi Energy FACTS Control Platform (FCP) <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-03.json"><strong
- Bransys ELD <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-01.json"><strong
- Schneider Electric NetBotz 5 750/755 <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-05.json"><strong
- Schneider Electric Modicon M340 Controller and Communication Modules <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-04.json"><strong
- Schneider Electric PowerChute Serial Shutdown <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-07.json"><strong
- ABB Ability Edgenius <p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-260-06.json"><strong
- MLflowのdspyとstatsmodelsフレーバーにおけるpickleのデシリアライズ制御回避の脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- Sentry Seerにおける攻撃者が制御する入力が管理者権限で実行される脆弱性 CERT/CCから本件に関するアドバイザリが公表されました。
- スマートフォンアプリ「東北電力 よりそうeねっと」におけるハードコードされた暗号鍵使用の脆弱性 東北電力株式会社が提供するスマートフォンアプリ「東北電力 よりそうeねっと」には、ハードコードされた暗号鍵使用の脆弱性が存在します。
- CISA Adds One Known Exploited Vulnerability to Catalog <p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-c
- CISA Adds Two Known Exploited Vulnerabilities to Catalog <p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities
- Using Cyber Decoys to Strengthen Detection and Response <div class="OutlineElement Ltr SCXW53093809 BCX8"> <p>CISA developed this guidance to help defensive teams at
- Weekly Report: a-blog cmsにパストラバーサルの脆弱性 a-blog cmsにパストラバーサルの脆弱性
- QNDにおける複数の脆弱性 クオリティソフト株式会社が提供するQNDには、複数の脆弱性が存在します。
対応の経緯をまとめた記事29件
- タイムズカーWebサイトへの不正アクセスについてまとめてみた <p>2026年9月25日、タイムズモビリティとパーク24は、カーシェアリングサービス「タイムズカー」のWebサイトが不正アクセスを受け、会員の個人情報が外部に漏えいした可能性があると公表しました。その後の調査で、対象シ
- AIエージェントによる利用者画像の外部サイト投稿についてまとめてみた <p>2026年9月25日、OpenAIは研究環境で稼働するAIエージェントが本来送信すべきでないデータを第三者サービスへ送信していたことを公表し、その中で利用者がアップロードした画像が画像ホスティングサイトに投稿されて
- 楽天証券のシステム不具合による意図しない資金移動についてまとめてみた <p>2026年9月25日、楽天証券は国内株式信用取引で「投資あんしんサービス」を利用する一部の顧客において、システム不具合により意図しない資金振替が発生していたと公表しました。ここでは関連する情報をまとめます。</p>
- JCOMのインターネット接続サービス障害についてまとめてみた <p>2026年9月23日、JCOMが提供するインターネット接続サービス等で、全国規模の通信障害が発生しました。JCOMは同日夜に復旧を確認し、翌24日には影響規模と原因を公表しています。ここでは関連する情報をまとめます
- 日米豪独7機関が公表した北朝鮮のサイバー攻撃グループ「WaterPlum」と北朝鮮IT労働者についてまとめてみた <p>警察庁と国家サイバー統括室(NCO)は2026年9月18日、米国、豪州、ドイツの関係機関とともに、北朝鮮を背景とするサイバー攻撃グループ「WaterPlum」(ウォータープラム)の攻撃手口と、北朝鮮IT労働者による
- GoogleのAIモデルが評価中に実在企業のシステムへ侵入した事案についてまとめてみた <p>2026年9月18日、Googleは自社のAI「Gemini」が第三者による能力評価の実施中に、実在する企業3社のシステムへ不正アクセスしていたことを明らかにしました。事案が発生したのは2026年5月。Google
- OpenAIのAIエージェントによる豪州政府Medicare統計ポータルへの不正アクセスについてまとめてみた <p>2026年9月24日、オーストラリアのアンソニー・アルバニージー首相は、OpenAIのAIエージェントが同国のMedicare統計報告サービスポータルに不正アクセスしていたことを公表しました。ここでは関連する情報を
- 美容医療プラットフォーム「Unni(カンナムオンニ)」への不正アクセスについてまとめてみた <p>2026年9月7日、美容医療の情報プラットフォーム「Unni(カンナムオンニ)」を運営するヒーリングペーパー(Healingpaper)は、同社サービスへの不正アクセスにより、日本の利用者約4万8000人を含む21
- 旭化成の元従業員による営業秘密の持ち出しについてまとめてみた <p>2026年9月17日、旭化成株式会社は、同社の元従業員が在職中に入手した機密情報を不正に持ち出し中国企業に流出させていたとして、不正競争防止法違反の疑いで愛知県警に逮捕されたと公表しました。ここでは関連する情報をま
Trust and the enticing consultancy offer In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value- NTTドコモによるAmazonへの顧客情報の無断提供についてまとめてみた <p>2026年9月16日、NTTドコモは、Amazonプライムの特典が付帯する料金プランの契約手続きにおいて、同意を得ないまま利用者の電話番号と契約する料金プラン名をアマゾンジャパン合同会社へ提供していたことを明らかに
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-sit- Gyazoへの不正アクセスについてまとめてみた <p>2026年9月16日、Helpfeelは、同社が提供する画像共有サービス「Gyazo」が不正アクセスを受け、ユーザー情報約2,362万件と画像に関するメタデータ約4.9億件が外部に流出したと公表しました。ここでは関
Securing the unpatchable in an age of AI-driven vulnerabilities Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult,- OpenAIのAIエージェントによるものとみられているRubyGemsへの不正なパッケージ大量投稿についてまとめてみた <p>2026年9月11日、セキュリティ研究者グループが、RubyGemsで5月に確認された不正なパッケージの大量投稿キャンペーンは内部のOpenAIエージェント群によるものとみられるとする報告書を公開しました。その後、
- 4件目も見つかったAnthropicの評価中AIモデルによる不正アクセス事案についてまとめてみた <p>2026年9月9日、Anthropicは研究報告を公表し、同じ評価パートナーが構築したサイバーセキュリティ評価の中で、自社モデルが実在する第三者システムへ不正アクセスした事例が新たに1件見つかり、計4件になったこと
- 沖縄県知事選挙をめぐる偽情報や誹謗中傷の拡散についてまとめてみた <p>2026年8月27日に告示され、9月13日に投開票された沖縄県知事選挙を巡り、候補者に関する偽情報や誤った情報、誹謗中傷がSNS上で相次いで拡散しました。生成AIによる偽画像やなりすましメール、発言や映像の切り取り
- デジタル庁のガバメントソリューションサービス(GSS)への不正アクセスについてまとめてみた <p>2026年9月11日、デジタル庁は、政府共通の業務実施環境「ガバメントソリューションサービス(GSS)」が外部からの不正アクセスを受け、取り扱っていた個人情報を含むファイルの一部が外部に漏えいした可能性があると公表
- AIエージェントによるドイツ語ウィキ「DseWiki」ののっとりについてまとめてみた <p>2026年9月4日、研究者グループが、OpenAI所属を示す名前を名乗るAIエージェント群がドイツ語ウィキ「DseWiki」など公開ウィキサイトへ大量の投稿を行い、サイトを即席の伝言板として悪用していたとする報告書
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affe- Project Glasswingと日本国内の状況についてまとめてみた <p>Anthropicは2026年4月7日、Claude Mythos Previewを用いてソフトウェアの脆弱性を発見する取り組み「Project Glasswing」の発足を発表しました。脆弱性の発見と悪用に高い能
- 鳥取県の放射線監視システムへのランサムウェア攻撃についてまとめてみた <p>2026年9月3日、鳥取県は、同県が運用する環境放射線モニタリングシステムがサイバー攻撃(ランサムウェアによる攻撃)を受け、システムの主監視局内の電子ファイルが暗号化される被害が発生したと公表しました。同システムは
- 大阪高裁で起きたMicrosoft Teams チーム作成時の大量誤登録についてまとめてみた <p>2026年9月4日、大阪高等裁判所は、特定の事件に関するMicrosoft Teamsのチームを作成する際に誤って約6000アカウントを登録し、通知からチームにアクセスした場合にメンバーのユーザー名やメールアドレス
- 10時間足らずで侵入されたAIエージェントによるランサムウェア攻撃についてまとめてみた <p>Palo Alto Networks Unit 42は2026年9月2日、ランサムウェア攻撃に対応したインシデントレスポンス事例を公表しました。攻撃者がフロンティアAIを用いてネットワークへの侵入からAI基盤の乗っ
- 監視機器の自動更新で起きた市立奈良病院のシステム障害についてまとめてみた <p>2026年4月、奈良市は、市立奈良病院でネットワーク監視装置が異常な通信を検知したことを受け電子カルテなどをネットワークから切り離し、外来診療や救急の受け入れを制限したと公表しました。発生当初は外部からのサイバー攻
- レノボの認証連携を悪用したDropboxの不正アクセスについてまとめてみた <p>2026年9月1日(米国時間)、Dropboxは一部利用者のアカウントが、レノボの認証連携(Lenovo ID)を経由した不正アクセスを受けていたことを、複数の報道機関への説明で明らかにしました<a href="#
- 2つの重要インフラ組織へ行われたレッドチーム評価についてまとめてみた <p>米国CISAは2026年8月25日、政府サービスおよび施設のセクターの組織(組織A)と上下水道セクターの組織(組織B)に対し類似の手口を用いて同時に実施したレッドチーム評価の結果を公表しました。ここでは関連する情報
- ランサムウェアグループによるCursorの悪用についてまとめてみた <p>ランサムウェアグループ「Aur0ra」(Auroraとも表記)のオペレータが、AIコーディングツール「Cursor」のAIエージェント機能を悪用していたことが、セキュリティ企業の報告などから明らかになりました。エー
セキュリティ報道240件
- WatchGuard製アクセスポイントに複数脆弱性 - 「クリティカル」も WatchGuard Technologiesが提供するアクセスポイント製品「WatchGuard AP」に複数の脆弱性が判明した。「クリティカル(Critical)」とされる脆弱性も含まれる。
Kiteworks patches critical flaw, brings customer systems online American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems afte
Apple patches CoreGraphics zero-day flaw exploited in attacks Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targete
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the O
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot OpenAI said it has made the decision to pause training of its most powerful models after one of its agents dur- 「macOS」にアップデート - iOSで悪用の可能性ある脆弱性に対処 Appleは現地時間2026年9月28日、「macOS Tahoe」「macOS Sequoia」向けに脆弱性を修正するセキュリティアップデートをリリースした。
- 「iOS 26.7.1」公開、脆弱性を修正 - 特定個人への攻撃で悪用か Appleは現地時間2026年9月28日、同社スマートデバイス向けに「iOS 26.7.1」「iPadOS 26.7.1」をリリースした。悪用された可能性がある脆弱性に対処したという。
Japan's Keio confirms ransomware attack disrupted business systems Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware a
JadePuffer agentic AI attacks target Azure, destroy cloud resources The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnais
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS tha
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vuln- 「SharePoint」「WordPress」など脆弱性5件の悪用を警告 - 米当局 米サイバーセキュリティインフラストラクチャセキュリティ庁(CISA)は、「NetScaler」「WordPress」「SharePoint」「RouterOS」に判明した脆弱性が悪用されているとして注意を呼びかけた。
- ランサム被害、一部グループ会社の営業システムに影響 - 京王電鉄 京王電鉄は、同社グループのサーバがランサムウェア攻撃を受け、一部でシステム障害が発生していることを明らかにした。鉄道運行への影響は否定している。
CISA orders feds to patch exploited Citrix flaws by Wednesday The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the week
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered i- 【特別企画】急激に進化する「AI」 - 見直すべき運用と変わらぬ防御原則 2026年に入り、「AI」が従来の予想を超える急激な進化を遂げている。AIによる大量の脆弱性報告など、セキュリティ分野に与えたインパクトは大きい。AIエージェントの過剰権限やシャドーAIといったリスクにも直面しており、セ
- 「Citrix NetScaler」に複数脆弱性 - 2件で悪用を確認、侵害調査を Cloud Software Groupが提供する「NetScaler ADC(旧Citrix ADC)」「NetScaler Gateway(旧Citrix Gateway)」に複数の脆弱性が明らかとなった。2件につい
Citrix confirms two NetScaler RCE zero-days exploited in attacks Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88
Cloudflare fixes Containers cross-tenant flaw exposing customer data Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid ac
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution ha
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mi
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin tha
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting- 「Next.js」の画像生成モジュールにRCEにつながる脆弱性 「Next.js」の画像生成モジュール「ImageResponse」の「Node.js実装」に脆弱性が明らかとなった。修正版が提供されている。
- 「PHP」に複数の脆弱性 - セキュリティアップデートが公開 「PHP」の開発チームは、複数の脆弱性が判明したことを受け、セキュリティアップデートを公開した。
- Adobe、7件のセキュリティアドバイザリを公開 Adobeは現地時間2026年9月22日、7件のセキュリティアドバイザリを公開した。6件のアドバイザリにおいて「クリティカル(Critical)」とされる脆弱性に対処したとしている。
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behi
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security fla
Kiteworks urges 6-hour server shutdown over potential zero-day attacks Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their se
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous serve
Elementor WordPress flaw lets attackers create admin accounts A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthe
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authe- 「ServiceNow AI Platform」にSQLiなど複数脆弱性 - 修正版を提供 「ServiceNow AI Platform」に5件の脆弱性が判明した。クリティカルとされる脆弱性も複数含まれており、ServiceNowでは利用者にアップデートを呼びかけている。
- 米CISA、「Adobe Commerce」「WSO2」の脆弱性悪用を警告 米当局は、AdobeのECプラットフォームやWSO2のAPI管理プラットフォームの脆弱性が悪用されているとして注意喚起を行った。米行政機関に対し、侵害状況の確認も含めて早急に対応するよう求めている。
- 「Chrome 154」公開、108件のセキュリティ修正 - 「クリティカル」が11件 Googleは現地時間2026年9月22日、ブラウザ「Chrome」の最新版となる「Chrome 154」を公開した。「クリティカル(Critical)」とされる脆弱性をはじめ、100件以上の修正を行っている。
- 「GitLab」がセキュリティアップデートを公開 - 深刻な脆弱性にも対処 GitLabは、同社の開発プラットフォーム「GitLab」に脆弱性が見つかったとしてアップデートをリリースした。深刻な脆弱性にも対処している。
- 「Apache Tomcat」のアップデートで脆弱性12件を解消 「Apache Tomcat」の開発チームは、セキュリティアップデートをリリースし、複数の脆弱性を解消した。CVEベースで12件を修正したという。
- 「NVIDIA Infrastructure Controller」に複数の脆弱性 - 「クリティカル」も ベアメタル環境のライフサイクル管理を自動化する「NVIDIA Infrastructure Controller(NICo)」に複数の脆弱性が明らかとなった。「クリティカル(Critical)」とされる脆弱性も含まれる。
- MSP向け管理ツール「ManageEngine OpManager MSP」に深刻な脆弱性 - 8月に修正済み Zohoがマネージドサービスプロバイダー(MSP)向けに提供している管理製品「ManageEngine OpManager MSP」に脆弱性が明らかとなった。8月のアップデートで修正を実施済みだという。
- ウェブサーバ「nginx」の「HTTP/3」モジュールに脆弱性 ウェブサーバ「nginx」の「HTTP/3」実装に脆弱性が明らかとなった。アップデートが提供されている。
FedRAMP VDR & VER: Daily Scans Are Only the Beginning FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, ti
Hackers now exploit critical Roundcube flaw in code injection attacks A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, acc
CISA: Ransomware gangs now exploiting critical TeamCity flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ra
OpenAI hacked Australian Medicare govt site, probed data providers OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and explo
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks fo
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search an
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360 ClickFix has become the most common way attackers get into enterprise networks, and it does it without an expl




