🔴 最新のCRITICAL (14件)
CISAが新たに「実際に悪用されている」と認定した脆弱性です。最優先で対応してください。
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
📅 2026-09-11 ⏰ 期限:2026-09-14
🔗 対策を確認する(CISA)JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
📅 2026-09-11 ⏰ 期限:2026-09-25
🔗 対策を確認する(CISA)JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
📅 2026-09-11 ⏰ 期限:2026-09-25
🔗 対策を確認する(CISA)GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
📅 2026-09-11 ⏰ 期限:2026-09-14
🔗 対策を確認する(CISA)MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
📅 2026-09-10 ⏰ 期限:2026-09-13
🔗 対策を確認する(CISA)MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
📅 2026-09-10 ⏰ 期限:2026-09-13
🔗 対策を確認する(CISA)Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.
📅 2026-09-09 ⏰ 期限:2026-09-12
🔗 対策を確認する(CISA)Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
📅 2026-09-09 ⏰ 期限:2026-09-12
🔗 対策を確認する(CISA)Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
📅 2026-09-09 ⏰ 期限:2026-09-23
🔗 対策を確認する(CISA)Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
📅 2026-09-09 ⏰ 期限:2026-09-12
🔗 対策を確認する(CISA)🟠 JPCERT/CC:日本向け注意喚起
🟡 JVN iPedia:国内製品脆弱性情報
取得できませんでした
⚠️ 免責事項
本情報はCISA KEV・JPCERT/CC・JVN iPediaの公開情報を収集・整理したものです。実際の対応は各情報源および専門家への相談のうえ行ってください。
一次情報源: CISA KEV / JPCERT/CC / JVN iPedia