セキュリティ診断、情報提供

セキュリティに関する情報の提供、ウェブ診断ツールを提供しているサイトです。

  アナウンス          一覧表示

更新日:2026年7月21日18:00

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日
1 - - (複数のベンダ) (複数の製品) 一部のHTTP/2サーバーにおけるフロー制御に起因したサービス拒否(DoS)の脆弱性 New - - 2026-07-21 14:05 2026-07-17
2 - - (複数のベンダ) (複数の製品) CISA ICS Advisory / ICS Medical Advisory(2026年07月16日) New - - 2026-07-21 14:05 2026-07-17
3 - - LMSYS Org SGLang SGLangにおけるPickleのデシリアライゼーションに関する脆弱性 New - - 2026-07-21 14:05 2026-07-17
4 6.5 警告
ネットワーク
Drupal AI Agents Drupalプラグイン「AI Agents」における不正な認証の脆弱性 New CWE-Other
その他
CVE-2026-13236 2026-07-21 12:21 2026-07-21
5 6.8 警告
物理
ソニー株式会社 2017年以前に出荷された一部のFeliCa ICチップ 非接触型ICカード技術FeliCaの一部のICチップにおける脆弱性 New CWE-Other
その他
CVE-2026-59776 2026-07-21 12:13 2026-07-21
6 7.8 重要
ローカル
マイクロソフト Microsoft Windows 11 24h2
Microsoft Windows Server 2012
Microsoft Windows 11 25h2
Microsoft Windows Server 2019
Microsoft …
WinSock 用 Windows Ancillary Function Driver の特権の昇格の脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-50312 2026-07-21 10:44 2026-07-14
7 7.8 重要
ローカル
マイクロソフト Microsoft Windows 11 24h2
Microsoft Windows Server 2012
Microsoft Windows 11 25h2
Microsoft Windows Server 2019
Microsoft …
Windows NTFS のリモートでコードが実行される脆弱性 New CWE-122
ヒープオーバーフロー
CVE-2026-50313 2026-07-21 10:44 2026-07-14
8 7.8 重要
ローカル
マイクロソフト Microsoft Office 2021 Long Term Servicing Channel Edition
Microsoft Office 2019
Microsoft 365 Apps
Microsoft Office 2024 …
Microsoft Office のリモート コードが実行される脆弱性 New CWE-416
解放済みメモリの使用
CVE-2026-50314 2026-07-21 10:44 2026-07-14
9 7.8 重要
ローカル
マイクロソフト Microsoft Windows Server 2025
Microsoft Windows 11 24h2
Microsoft Windows 11 26h1
Microsoft Windows 11 25h2
Windows Image Acquisition の特権の昇格の脆弱性 New CWE-476
NULL ポインタデリファレンス
CVE-2026-50315 2026-07-21 10:44 2026-07-14
10 5.5 警告
ローカル
マイクロソフト Microsoft Windows 11 24h2
Microsoft Windows 11 25h2
Microsoft Windows 10 22h2
Microsoft Windows Server 2022
Microsoft Wind…
Windows カーネルの情報漏えいの脆弱性 New CWE-532
ログファイルからの情報漏えい
CVE-2026-50316 2026-07-21 10:44 2026-07-14

更新日":2026年7月22日4:02

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日
1 7.8 HIGH
ローカル
microsoft windows_subsystem_for_linux Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. New CWE-126
バッファオーバーリード
CVE-2026-57968
2026-07-21 03:39 2026-07-15
2 4.7 MEDIUM
ローカル
microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. New CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-57973
2026-07-21 03:39 2026-07-15
3 6.5 MEDIUM
ネットワーク
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
windows_server_2019<…
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. New CWE-908
初期化されていないリソースの使用
CVE-2026-57982
2026-07-21 03:39 2026-07-15
4 7.0 HIGH
ローカル
microsoft windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2022
windows_server_2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. New CWE-362
競合状態
CVE-2026-58527
2026-07-21 03:38 2026-07-15
5 4.6 MEDIUM
物理
microsoft windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2019
windows_server_2022
windows_server_2025
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. New CWE-125
境界外読み取り
CVE-2026-58528
2026-07-21 03:33 2026-07-15
6 7.8 HIGH
ローカル
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2016
windows_server_2019
windows_server_2022<…
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. New CWE-122
ヒープオーバーフロー
CVE-2026-58530
2026-07-21 03:28 2026-07-15
7 7.5 HIGH
ネットワーク
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
windows_server_2019<…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. New CWE-362
CWE-416
競合状態
解放済みメモリの使用
CVE-2026-58531
2026-07-21 03:26 2026-07-15
8 9.8 CRITICAL
ネットワーク
langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabl… New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-9103
2026-07-21 03:22 2026-07-18
9 9.9 CRITICAL
ネットワーク
langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists b… New CWE-94
コード・インジェクション
CVE-2026-9135
2026-07-21 03:22 2026-07-18
10 - - - The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesyst… New CWE-59
リンク解釈の問題
CVE-2026-8170
2026-07-21 03:16 2026-07-21

対象期間 : 2026-06-01 〜 2026-10-31

No 名前 通常サポート セキュリティサポート 延長サポート
1 注意 MariaDB 10.6 2026-06-30
2 注意 SQL Server 2016 Service Pack 2 2021-07-13 2026-07-14
3 Azul Zulu Builds of OpenJDK 26 2026-09-30
4 Oracle JDK 11 (LTS) 2023-09-30 2026-09-30
5 Python3.10 2026-10-31
2026-7-21 JST
メディア・ニュース
No イメージ 名前 URL 変更部分の抜粋 タグ
1 Ars Technica https://arstechnica.com/ I tried to be positive,F1 in Belgium: Machine learning algorithms are ruining the sport,Many will say Spa is the best racetrack on earth, but not for these F1 cars.,Jonathan M. Gitlin,–,7/20/2026,|,75 ...
  • English
  • News
  • 海外
  • ブログ
  • サイト情報収集
2 Bleeping Computer® https://www.bleepingcomputer.com/ Estée Lauder discloses data breach via Oracle E-Business flaw,SonicWall SMA1000 flaws exploited as zero-days to push custom malware,Hackers steal $23.7 million in crypto from Ostium in off-chain attac ...
  • English
  • News
  • 海外
  • 情報提供
3 cnet https://www.cnet.com/ Skip to content,Open,Close,Your Guide,To a Better Future,AI,Tech,Home,Entertainment,Reviews,Best Products,Deals,Search,Search,Close,AI,AI Atlas,Best AI Image Generators,Best AI Chatbots,Best AI Websit ...
  • English
  • News
  • 海外
  • ブログ
4 Cybersecurity News https://securityonline.info/ July 20, 2026,Mid-July 2026: Weekly Threat Intelligence Report,Do Son,July 20, 2026,0,Weekly Recap,Codex Cuts Its Context Window to 272K and Forbids rm -rf $HOME After Home-Directory Deletions,Do Son, ...
  • English
  • News
  • 海外
  • 情報提供
5 Engadget https://www.engadget.com/ Wearables,Meta Glasses review: A bit less polish, a lot more baggage,Meta's glasses deliver the same functionality as its Ray-Ban models but don't quite feel as premium.,By,Karissa Bell,Read More,0,En ...
  • English
  • News
  • 海外
  • ブログ
6 Gizmodo https://gizmodo.com/ Hugging Face: We Used AI to Catch the First Confirmed AI Agent Breach of a Major AI Platform,The company says the attack was carried out end to end by an autonomous AI-agent system.,Artificial Intelli ...
  • English
  • News
  • 海外
  • ブログ
7 HELPNETSECURITY https://www.helpnetsecurity.com/ The Odyssey piracy scams surface hours after its theatrical debut,July 20, 2026,HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel,July 20, 2026,Paidwork breach exposes sensit ...
  • English
  • News
  • 海外
  • 情報提供
8 Japan Security Summit https://japansecuritysummit.org/ 6月のサイバー攻撃、世界で前年比17%増 日本は30%増...,2026.07.21,編集部,ソフトウェア協会、医療機関向けセキュリティ研修を開始 被...,2026.07.21,編集部,アサヒグループHD、サイバー攻撃による個人情報漏えいのお...,2026.07.20,編集部
  • Japanese
  • News
  • 組織
9 Mashable https://mashable.com/ it's happening,Samsung Galaxy Unpacked is almost here: Everything we expect from the July 22 event,a dynamite six minutes,The internet reacts to the first-ever World Cup Halftime show,start of week en ...
  • English
  • News
  • 海外
  • ブログ
10 ScanNetSecurity https://scan.netsecurity.ne.jp/ 2026.07.21(火),調査・レポート・白書・ガイドライン,2026年7月21日,Okta Japan、企業における AI ツールの利用実態調査「Okta Enterprise AI Index」発表,Okta Japan株式会社は7月17日、企業におけるAIツールの利用実態を調査した「Okta Enterprise AI Index」を発表した。,AI エージェント時代における Okta の ...
  • Japanese
  • News
  • 情報提供
11 Schneier on Security https://www.schneier.com/ On Flock License Plate Tracking Cameras,A recent story of a writer who was,mistakenly,identified, tracked, and arrested using data from Flock cameras has gone viral.,The New Jersey plates that were al ...
  • English
  • News
  • 海外
  • ブログ
12 scmagazine https://www.scmagazine.com/ (Credit: Robert – stock.adobe.com),More Mythos-like models are coming — what organizations can do now,Laura,French,July 20, 2026,These capabilities may be impossible to contain, forcing defenders to c ...
  • English
  • News
  • 海外
  • 情報提供
13 securityledger.com https://securityledger.com/ Monday, July 20, 2026,July 20, 2026,|,Paul Roberts,Edge Devices Are Your Cyber Underbelly. Here’s Why.,In this episode of the podcast, host Paul Roberts interviews Nishawn Smagh of the firm GreyNoise ...
  • English
  • News
  • 海外
  • 情報提供
14 securityweek https://www.securityweek.com/ CONFERENCE,Cloud & Data Security Summit - Watch Sessions on Demand,Neo Emerges From Stealth With $100M to Control and Secure Enterprise AI Software,Neo raised money across seed and Series A funding ro ...
  • English
  • News
  • 海外
  • 情報提供
15 TechCrunch https://techcrunch.com/ OpenAI is scared of open-weight models. Should the US be?,Tim Fernholz,4 hours ago,AI,AI’s most important protocol is getting a little bit easier to use,Russell Brandom,2 hours ago,AI,Google is workin ...
  • English
  • News
  • 海外
  • ブログ
  • サイト情報収集
16 TechNadu.com https://www.technadu.com/ Wp2shell: The Unauthenticated WordPress Exploit That Needs No Login, No Plugins, Just a Vulnerable Core,By,Lore Apostol,|,Published,Kenya's Presidential Website Hit by Cyber Incident, Government Says ...
  • English
  • News
  • 海外
  • 情報提供
17 TechRadar https://www.techradar.com/ Avengers: Doomsday official trailer breakdown live — all of our analysis and theories on the new Marvel movie's latest teaser,Marvel has publicly revealed the official trailer for Avengers: Doomsday — ...
  • English
  • News
  • 海外
  • ブログ
18 The Verge https://www.theverge.com/ SpaceX in your index fund, explained,Index funds are supposed to be the safest way to invest — does SpaceX change that?,Elizabeth Lopatto,An hour ago,China delivers a one-two punch to America’s AI dom ...
  • English
  • News
  • 海外
  • ブログ
19 wired https://www.wired.com/ THE BIG STORY,Kids These Days,Elite Young Runners Are Becoming Freakishly Fast. Welcome to ‘Trackflation’,Four-minute miles are almost routine. Middle schoolers are beating college runners. Inside the ...
  • English
  • News
  • ブログ
セキュリティ関連企業
ツール
ブログ
No イメージ 名前 URL 変更部分の抜粋 タグ
1 Qualys Security Blog https://blog.qualys.com/ Farah Syed,July 20, 2026,- 18 min read,Top Five Compliance Audit Software and Tools: Mastering Modern Regulatory Risk,Posted in,Product and Tech,4,3,24,2
  • English
  • 大手
  • 海外
  • ブログ
  • 情報提供
2 Rapid7 ブログ https://www.rapid7.com/blog/ 3895,Threat Research,From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab,Anna Širokova, Jan Recinsky
  • English
  • 大手
  • 海外
  • 会社
  • ブログ
  • 情報提供
3 Sans Blog https://www.sans.org/blog/ 233,102,52,953,20 Jul 2026,When Frontier Models Say No: What the Hugging Face Breach Teaches Us About Local LLMs,Blog,Artificial Intelligence,20 Jul 2026,Mari DeGrazia,AI Can Find Bugs, But Human Know ...
  • English
  • 大手
  • 海外
  • ブログ
  • 情報提供
4 Whitehat Security ブログ https://www.blackduck.com:443/blog.html Security News,Polaris achieves TX-RAMP certification: A milestone in our public sector commitment,Read the blog post
  • English
  • 海外
  • ブログ
  • 情報提供
5 セキュリティホールメモ http://www.st.ryukoku.ac.jp/~kjm/security/memo/ Last modified: Mon Jul 20 18:44:43 2026,■,2026.07.20,》,ユーザーをEdgeに誘導するためのMicrosoftの手法を国別に比較したレポートが公開中,(やじうま Watch, 7/17),ユーザーの錯誤につながる行為を法律で禁止している地域については、それに基づいて対応を変えていることが明らかになっている。,法整備の重要性。,■,いろいろ (20 ...
  • Japanese
  • 著名人
  • 著名人
  • ブログ
  • ブログ
  • 情報提供
  • 情報提供
組織
会議
No イメージ 名前 URL 変更部分の抜粋 タグ
1 Positive Hack Days https://www.phdays.com/ Документы и правила
  • Russia
  • 組織
やられサイト
No イメージ 名前 URL 変更部分の抜粋 タグ
1 easybuggy4django https://github.com/k-tamura/easybuggy4django/ Code Quality,Enforce quality at merge
  • Japanese
  • CTF
  • 教育
Firewall