← 最新レポートに戻る | 📚 アーカイブ一覧

🔍 脆弱性情報レポート

📅 レポート日: 2026年07月06日

📊 重要度サマリー

🔴 CRITICAL(即時対応・24時間以内)6件
🟠 高(優先対応・72時間以内)0件
🟡 中(計画対応・1週間以内)0件
🟢 低(モニタリング・月次確認)0件
合計6件

🔴 この週のCRITICAL(6件)

この週にCISAが新たに「実際に悪用されている」と認定した脆弱性です。

🔴 CRITICAL 📋 特集記事 CVE-2026-56291 | Forms (Balbooa)

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

📅 2026-07-10 ⏰ 期限:2026-07-13

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-48939 | iCagenda (iCagenda)

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

📅 2026-07-10 ⏰ 期限:2026-07-13

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-48908 | SP Page Builder (JoomShaper)

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

📅 2026-07-07 ⏰ 期限:2026-07-10

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-55255 | Langflow (Langflow)

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

📅 2026-07-07 ⏰ 期限:2026-07-10

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-56290 | Page Builder (Joomlack)

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

📅 2026-07-07 ⏰ 期限:2026-07-10

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-48282 | ColdFusion (Adobe)

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

📅 2026-07-07 ⏰ 期限:2026-07-10

🔗 対策を確認する(CISA)

⚠️ 免責事項

本情報はCISA KEV・JPCERT/CC・JVN iPediaの公開情報を収集・整理したものです。 実際の対応は各情報源および専門家への相談のうえ行ってください。

CISA KEV / JPCERT/CC / JVN iPedia