← 最新レポートに戻る | 📚 アーカイブ一覧

🔍 脆弱性情報レポート

📅 レポート日: 2026年07月13日

📊 重要度サマリー

🔴 CRITICAL(即時対応・24時間以内)10件
🟠 高(優先対応・72時間以内)0件
🟡 中(計画対応・1週間以内)0件
🟢 低(モニタリング・月次確認)0件
合計10件

🔴 この週のCRITICAL(10件)

この週にCISAが新たに「実際に悪用されている」と認定した脆弱性です。

🔴 CRITICAL 📋 特集記事 CVE-2026-58644 | SharePoint (Microsoft)

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

📅 2026-07-16 ⏰ 期限:2026-07-19

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-25089 | FortiSandbox (Fortinet)

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

📅 2026-07-16 ⏰ 期限:2026-07-19

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-39808 | FortiSandbox (Fortinet)

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

📅 2026-07-16 ⏰ 期限:2026-07-19

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-46817 | E-Business Suite (Oracle)

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

📅 2026-07-15 ⏰ 期限:2026-07-18

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2023-4346 | KNX Protocol Connection Authorization Option 1 (KNX Association)

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.

📅 2026-07-15 ⏰ 期限:2026-07-29

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-56155 | Active Directory Federation Services (Microsoft)

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

📅 2026-07-14 ⏰ 期限:2026-07-28

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-56164 | SharePoint Server (Microsoft)

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

📅 2026-07-14 ⏰ 期限:2026-07-17

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-15409 | SMA1000 Appliances (SonicWall)

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

📅 2026-07-14 ⏰ 期限:2026-07-17

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-15410 | SMA1000 Appliances (SonicWall)

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

📅 2026-07-14 ⏰ 期限:2026-07-17

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2008-4128 | IOS (Cisco)

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.

📅 2026-07-13 ⏰ 期限:2026-07-16

🔗 対策を確認する(CISA)

⚠️ 免責事項

本情報はCISA KEV・JPCERT/CC・JVN iPediaの公開情報を収集・整理したものです。 実際の対応は各情報源および専門家への相談のうえ行ってください。

CISA KEV / JPCERT/CC / JVN iPedia