| 🔴 CRITICAL(即時対応・24時間以内) | 6件 |
| 🟠 高(優先対応・72時間以内) | 0件 |
| 🟡 中(計画対応・1週間以内) | 0件 |
| 🟢 低(モニタリング・月次確認) | 0件 |
| 合計 | 6件 |
この週にCISAが新たに「実際に悪用されている」と認定した脆弱性です。
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
📅 2026-07-22 ⏰ 期限:2026-07-25
🔗 対策を確認する(CISA)Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
📅 2026-07-22 ⏰ 期限:2026-07-25
🔗 対策を確認する(CISA)WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
📅 2026-07-21 ⏰ 期限:2026-08-04
🔗 対策を確認する(CISA)WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
📅 2026-07-21 ⏰ 期限:2026-07-24
🔗 対策を確認する(CISA)Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
📅 2026-07-21 ⏰ 期限:2026-07-24
🔗 対策を確認する(CISA)DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
📅 2026-07-21 ⏰ 期限:2026-07-24
🔗 対策を確認する(CISA)本情報はCISA KEV・JPCERT/CC・JVN iPediaの公開情報を収集・整理したものです。 実際の対応は各情報源および専門家への相談のうえ行ってください。