| 🔴 CRITICAL(即時対応・24時間以内) | 2件 |
| 🟠 高(優先対応・72時間以内) | 0件 |
| 🟡 中(計画対応・1週間以内) | 0件 |
| 🟢 低(モニタリング・月次確認) | 0件 |
| 合計 | 2件 |
この週にCISAが新たに「実際に悪用されている」と認定した脆弱性です。
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
📅 2026-07-27 ⏰ 期限:2026-08-10
🔗 対策を確認する(CISA)Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
📅 2026-07-27 ⏰ 期限:2026-07-30
🔗 対策を確認する(CISA)本情報はCISA KEV・JPCERT/CC・JVN iPediaの公開情報を収集・整理したものです。 実際の対応は各情報源および専門家への相談のうえ行ってください。