🔴 最新のCRITICAL (4件)
CISAが新たに「実際に悪用されている」と認定した脆弱性です。最優先で対応してください。
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
📅 2026-07-27 ⏰ 期限:2026-08-10
🔗 対策を確認する(CISA)Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
📅 2026-07-27 ⏰ 期限:2026-07-30
🔗 対策を確認する(CISA)Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
📅 2026-07-22 ⏰ 期限:2026-07-25
🔗 対策を確認する(CISA)Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
📅 2026-07-22 ⏰ 期限:2026-07-25
🔗 対策を確認する(CISA)🟠 JPCERT/CC:日本向け注意喚起
🟡 JVN iPedia:国内製品脆弱性情報
取得できませんでした
⚠️ 免責事項
本情報はCISA KEV・JPCERT/CC・JVN iPediaの公開情報を収集・整理したものです。実際の対応は各情報源および専門家への相談のうえ行ってください。
一次情報源: CISA KEV / JPCERT/CC / JVN iPedia