← 最新レポートに戻る

🔍 脆弱性情報レポート

📅 2026年09月13日 | 毎週月曜 自動更新 | 📚 過去レポート一覧 | プライバシーポリシー

📊 今週の重要度サマリー

🔴 CRITICAL(即時対応・24時間以内)14件
🟠 高(優先対応・72時間以内)2件
🟡 中(計画対応・1週間以内)1件
🟢 低(モニタリング・月次確認)7件
合計24件

🔴 最新のCRITICAL (14件)

CISAが新たに「実際に悪用されている」と認定した脆弱性です。最優先で対応してください。

🔴 CRITICAL CVE-2026-84869 | ScreenConnect (ConnectWise)

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.

📅 2026-09-11 ⏰ 期限:2026-09-14

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-42016 | Artifactory (JFrog)

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

📅 2026-09-11 ⏰ 期限:2026-09-25

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-42018 | Artifactory (JFrog)

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

📅 2026-09-11 ⏰ 期限:2026-09-25

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-85706 | Community Edition and Enterprise Edition (GitLab)

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.

📅 2026-09-11 ⏰ 期限:2026-09-14

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-86060 | RouterOS (MikroTik)

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.

📅 2026-09-10 ⏰ 期限:2026-09-13

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-67277 | RouterOS (MikroTik)

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.

📅 2026-09-10 ⏰ 期限:2026-09-13

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-19490 | NetScaler (Citrix)

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

📅 2026-09-09 ⏰ 期限:2026-09-12

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2025-25249 | Multiple Products (Fortinet)

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

📅 2026-09-09 ⏰ 期限:2026-09-12

🔗 対策を確認する(CISA)
🔴 CRITICAL CVE-2026-87491 | Chromium V8 (Google)

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

📅 2026-09-09 ⏰ 期限:2026-09-23

🔗 対策を確認する(CISA)
🔴 CRITICAL 📋 特集記事 CVE-2026-20079 | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco)

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

📅 2026-09-09 ⏰ 期限:2026-09-12

🔗 対策を確認する(CISA)

🟠 JPCERT/CC:日本向け注意喚起

🟢 低 注意喚起: Adobe AcrobatおよびReaderの脆弱性(APSB26-141)に関する注意喚起 (公開)

🔗 詳細(JPCERT/CC)

🟢 低 注意喚起: 2026年9月マイクロソフトセキュリティ更新プログラムに関する注意喚起 (公開)

🔗 詳細(JPCERT/CC)

🟠 高 注意喚起: NetScaler ADCおよびNetScaler Gatewayにおけるリモートコード実行につながる脆弱性(CVE-2026-8452)に関する注意喚起 (公開)

🔗 詳細(JPCERT/CC)

🟡 中 注意喚起: MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)に関する注意喚起 (公開)

🔗 詳細(JPCERT/CC)

🟢 低 注意喚起: 2026年8月マイクロソフトセキュリティ更新プログラムに関する注意喚起 (公開)

🔗 詳細(JPCERT/CC)

🟡 JVN iPedia:国内製品脆弱性情報

取得できませんでした

⚠️ 免責事項

本情報はCISA KEV・JPCERT/CC・JVN iPediaの公開情報を収集・整理したものです。実際の対応は各情報源および専門家への相談のうえ行ってください。

一次情報源: CISA KEV / JPCERT/CC / JVN iPedia