最終取得: 2026-07-16 07:40(キャッシュ 30分)
| CVE | ベンダー / 製品 | 脆弱性名 | 追加日 | リンク |
|---|---|---|---|---|
| CVE-2026-46817 NEW | Oracle E-Business Suite |
Oracle E-Business Suite Improper Privilege Management Vulnerability | 2026-07-15 | NVD 一次情報 |
| CVE-2023-4346 NEW | KNX Association KNX Protocol Connection Authorization Option 1 |
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | 2026-07-15 | NVD 一次情報 |
| CVE-2026-56155 NEW | Microsoft Active Directory Federation Services |
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | 2026-07-14 | NVD 一次情報 |
| CVE-2026-56164 NEW | Microsoft SharePoint Server |
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | 2026-07-14 | NVD 一次情報 |
| CVE-2026-15409 NEW | SonicWall SMA1000 Appliances |
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 2026-07-14 | NVD 一次情報 |
| CVE-2026-15410 NEW | SonicWall SMA1000 Appliances |
SonicWall SMA1000 Appliances Code Injection Vulnerability | 2026-07-14 | NVD 一次情報 |
| CVE-2008-4128 NEW | Cisco IOS |
Cisco IOS Cross-Site Request Forgery Vulnerability | 2026-07-13 | NVD 一次情報 |
| CVE-2026-56291 NEW | Balbooa Forms |
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-07-10 | NVD 一次情報 |
| CVE-2026-48939 NEW | iCagenda iCagenda |
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-07-10 | NVD 一次情報 |
| CVE-2026-48908 | JoomShaper SP Page Builder |
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | 2026-07-07 | NVD 一次情報 |
| CVE-2026-55255 | Langflow Langflow |
Langflow Authorization Bypass Through User-Controlled Key Vulnerability | 2026-07-07 | NVD 一次情報 |
| CVE-2026-56290 | Joomlack Page Builder |
Joomlack Page Builder Improper Access Control Vulnerability | 2026-07-07 | NVD 一次情報 |
| CVE-2026-48282 | Adobe ColdFusion |
Adobe ColdFusion Path Traversal Vulnerability | 2026-07-07 | NVD 一次情報 |
| CVE-2026-45659 | Microsoft SharePoint Server |
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | 2026-07-01 | NVD 一次情報 |
| CVE-2026-48558 | SimpleHelp SimpleHelp |
SimpleHelp Authentication Bypass Vulnerability | 2026-06-29 | NVD 一次情報 |
| CVE-2026-12569 | PTC Windchill and FlexPLM |
PTC Windchill and FlexPLM Improper Input Validation Vulnerability | 2026-06-25 | NVD 一次情報 |
| CVE-2026-20230 | Cisco Unified Communications Manager |
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | 2026-06-25 | NVD 一次情報 |
| CVE-2025-67038 | Lantronix EDS5000 |
Lantronix EDS5000 Code Injection Vulnerability | 2026-06-23 | NVD 一次情報 |
| CVE-2026-34910 | Ubiquiti UniFi OS |
Ubiquiti UniFi OS Improper Input Validation Vulnerability | 2026-06-23 | NVD 一次情報 |
| CVE-2026-34909 | Ubiquiti UniFi OS |
Ubiquiti UniFi OS Path Traversal Vulnerability | 2026-06-23 | NVD 一次情報 |
| CVE-2026-34908 | Ubiquiti UniFi OS |
Ubiquiti UniFi OS Improper Access Control Vulnerability | 2026-06-23 | NVD 一次情報 |
| CVE-2026-20253 | Splunk Enterprise |
Splunk Enterprise Missing Authentication for Critical Function Vulnerability | 2026-06-18 | NVD 一次情報 |
| CVE-2026-48907 | Widget Factory Joomla Content Editor |
Widget Factory Joomla Content Editor Improper Access Control Vulnerability | 2026-06-16 | NVD 一次情報 |
| CVE-2026-54420 | LiteSpeed cPanel Plugin |
LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability | 2026-06-15 | NVD 一次情報 |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager |
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability | 2026-06-15 | NVD 一次情報 |
| CVE-2026-35273 ランサム | Oracle PeopleSoft Enterprise PeopleTools |
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability | 2026-06-12 | NVD 一次情報 |
| CVE-2026-10520 | Ivanti Sentry |
Ivanti Sentry OS Command Injection Vulnerability | 2026-06-11 | NVD 一次情報 |
| CVE-2026-11645 | Google Chromium V8 |
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability | 2026-06-09 | NVD 一次情報 |
| CVE-2026-7473 | Arista Extensible Operating System |
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability | 2026-06-09 | NVD 一次情報 |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager |
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability | 2026-06-09 | NVD 一次情報 |
| CVE-2026-42271 | BerriAI LiteLLM |
BerriAI LiteLLM Command Injection Vulnerability | 2026-06-08 | NVD 一次情報 |
| CVE-2026-50751 ランサム | Check Point Security Gateway |
Check Point Security Gateway Improper Authentication Vulnerability | 2026-06-08 | NVD 一次情報 |
| CVE-2026-28318 | SolarWinds Serv-U |
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability | 2026-06-05 | NVD 一次情報 |
| CVE-2026-45247 | Mirasvit Mirasvit Full Page Cache Warmer |
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | 2026-06-03 | NVD 一次情報 |
| CVE-2022-0492 | Linux Kernel |
Linux Kernel Improper Authentication Vulnerability | 2026-06-02 | NVD 一次情報 |
| CVE-2025-48595 | Android Framework |
Android Framework Integer Overflow Vulnerability | 2026-06-02 | NVD 一次情報 |
| CVE-2024-21182 | Oracle WebLogic Server |
Oracle WebLogic Server Unspecified Vulnerability | 2026-06-01 | NVD 一次情報 |
| CVE-2026-0257 | Palo Alto Networks PAN-OS |
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability | 2026-05-29 | NVD 一次情報 |
| CVE-2026-48027 ランサム | Nx Nx Console |
Nx Console Embedded Malicious Code Vulnerability | 2026-05-27 | NVD 一次情報 |
| CVE-2026-45321 ランサム | TanStack TanStack |
TanStack Unspecified Vulnerability | 2026-05-27 | NVD 一次情報 |
| CVE-2026-8398 | Daemon Daemon Tools Lite |
Daemon Tools Lite Embedded Malicious Code Vulnerability | 2026-05-27 | NVD 一次情報 |
| CVE-2026-48172 | LiteSpeed cPanel Plugin |
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability | 2026-05-26 | NVD 一次情報 |
| CVE-2026-9082 | Drupal Core |
Drupal Core SQL Injection Vulnerability | 2026-05-22 | NVD 一次情報 |
| CVE-2025-34291 | Langflow Langflow |
Langflow Origin Validation Error Vulnerability | 2026-05-21 | NVD 一次情報 |
| CVE-2026-34926 | Trend Micro Apex One |
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | 2026-05-21 | NVD 一次情報 |
| CVE-2008-4250 | Microsoft Windows |
Microsoft Windows Buffer Overflow Vulnerability | 2026-05-20 | NVD 一次情報 |
| CVE-2009-1537 | Microsoft DirectX |
Microsoft DirectX NULL Byte Overwrite Vulnerability | 2026-05-20 | NVD 一次情報 |
| CVE-2009-3459 | Adobe Acrobat and Reader |
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability | 2026-05-20 | NVD 一次情報 |
| CVE-2010-0249 | Microsoft Internet Explorer |
Microsoft Internet Explorer Use-After-Free Vulnerability | 2026-05-20 | NVD 一次情報 |
| CVE-2010-0806 | Microsoft Internet Explorer |
Microsoft Internet Explorer Use-After-Free Vulnerability | 2026-05-20 | NVD 一次情報 |
| CVE-2026-41091 | Microsoft Defender |
Microsoft Defender Link Following Vulnerability | 2026-05-20 | NVD 一次情報 |
| CVE-2026-45498 | Microsoft Defender |
Microsoft Defender Denial of Service Vulnerability | 2026-05-20 | NVD 一次情報 |
| CVE-2026-42897 | Microsoft Microsoft |
Microsoft Exchange Server Cross-Site Scripting Vulnerability | 2026-05-15 | NVD 一次情報 |
| CVE-2026-20182 | Cisco Catalyst SD-WAN |
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability | 2026-05-14 | NVD 一次情報 |
| CVE-2026-42208 | BerriAI LiteLLM |
BerriAI LiteLLM SQL Injection Vulnerability | 2026-05-08 | NVD 一次情報 |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) |
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | 2026-05-07 | NVD 一次情報 |
| CVE-2026-0300 | Palo Alto Networks PAN-OS |
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability | 2026-05-06 | NVD 一次情報 |
| CVE-2026-31431 | Linux Kernel |
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability | 2026-05-01 | NVD 一次情報 |
| CVE-2026-41940 ランサム | WebPros cPanel & WHM and WP2 (WordPress Squared) |
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability | 2026-04-30 | NVD 一次情報 |
| CVE-2024-1708 ランサム | ConnectWise ScreenConnect |
ConnectWise ScreenConnect Path Traversal Vulnerability | 2026-04-28 | NVD 一次情報 |
| CVE-2026-32202 | Microsoft Windows |
Microsoft Windows Protection Mechanism Failure Vulnerability | 2026-04-28 | NVD 一次情報 |
| CVE-2025-29635 | D-Link DIR-823X |
D-Link DIR-823X Command Injection Vulnerability | 2026-04-24 | NVD 一次情報 |
| CVE-2024-7399 | Samsung MagicINFO 9 Server |
Samsung MagicINFO 9 Server Path Traversal Vulnerability | 2026-04-24 | NVD 一次情報 |
| CVE-2024-57728 ランサム | SimpleHelp SimpleHelp |
SimpleHelp Path Traversal Vulnerability | 2026-04-24 | NVD 一次情報 |
| CVE-2024-57726 ランサム | SimpleHelp SimpleHelp |
SimpleHelp Missing Authorization Vulnerability | 2026-04-24 | NVD 一次情報 |
| CVE-2026-39987 | Marimo Marimo |
Marimo Remote Code Execution Vulnerability | 2026-04-23 | NVD 一次情報 |
| CVE-2026-33825 ランサム | Microsoft Defender |
Microsoft Defender Insufficient Granularity of Access Control Vulnerability | 2026-04-22 | NVD 一次情報 |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manger |
Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager |
Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2025-2749 | Kentico Kentico Xperience |
Kentico Xperience Path Traversal Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2023-27351 ランサム | PaperCut NG/MF |
PaperCut NG/MF Improper Authentication Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2025-48700 | Synacor Zimbra Collaboration Suite (ZCS) |
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager |
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2025-32975 | Quest KACE Systems Management Appliance (SMA) |
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2024-27199 ランサム | JetBrains TeamCity |
JetBrains TeamCity Relative Path Traversal Vulnerability | 2026-04-20 | NVD 一次情報 |
| CVE-2026-34197 | Apache ActiveMQ |
Apache ActiveMQ Improper Input Validation Vulnerability | 2026-04-16 | NVD 一次情報 |
| CVE-2009-0238 | Microsoft Office |
Microsoft Office Remote Code Execution | 2026-04-14 | NVD 一次情報 |
| CVE-2026-32201 | Microsoft SharePoint Server |
Microsoft SharePoint Server Improper Input Validation Vulnerability | 2026-04-14 | NVD 一次情報 |
| CVE-2012-1854 | Microsoft Visual Basic for Applications (VBA) |
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability | 2026-04-13 | NVD 一次情報 |
| CVE-2025-60710 | Microsoft Windows |
Microsoft Windows Link Following Vulnerability | 2026-04-13 | NVD 一次情報 |
最終取得: 2026-07-16 07:40(キャッシュ 30分)
| 公開日 | アドバイザリ | CVE |
|---|---|---|
| 2026-07-14 |
Buffer overread in authd and wad daemon
CVSSv3 Score:
4.1
A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticate… |
— |
| 2026-07-14 |
Cross-Site Scripting in Domain parameter
CVSSv3 Score:
5.3
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in… |
— |
| 2026-07-14 |
Header injection in Web Filter warning page
CVSSv3 Score:
3.4
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CW… |
— |
| 2026-07-14 |
Header injection in captive portal authentication form
CVSSv3 Score:
3.1
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CW… |
— |
| 2026-07-14 |
Missed certificate verification in AD Connector communication with FortiClient EMS
CVSSv3 Score:
6.7
An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthent… |
— |
| 2026-07-14 |
Out of bounds read in GUI
CVSSv3 Score:
7.0
An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated att… |
— |
| 2026-07-14 |
Path traversal in CLI command allows deletion of root file system
CVSSv3 Score:
5.0
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] i… |
— |
| 2026-07-14 |
SSL-VPN Reflected XSS
CVSSv3 Score:
6.1
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE… |
— |
| 2026-07-14 |
Stack Buffer Overflow in Log Report
CVSSv3 Score:
5.9
A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a priv… |
— |
| 2026-07-14 |
Supers override fails to properly override supervisor address
CVSSv3 Score:
6.9
An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIE… |
— |
| 2026-07-14 |
Unauthenticated VNC access exposed on all interfaces
CVSSv3 Score:
7.7
An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSanbox may allow an unauthenticate… |
— |
| 2026-02-10 |
LDAP authentication bypass in Agentless VPN and FSSO
CVSSv3 Score:
7.5
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauth… |
— |
| 2025-06-10 |
Information Disclosure on SSLVPN endpoint
CVSSv3 Score:
3.9
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN w… |
— |
| 2026-06-09 |
Improper access control in API endpoints
CVSSv3 Score:
6.2
An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privile… |
— |
| 2026-06-09 |
Restricted CLI escape using Lua
CVSSv3 Score:
6.0
An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and Fo… |
— |
| 2026-06-09 |
Second-Order OS Command Injection via JSON Input on start vnc feature
CVSSv3 Score:
9.1
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbo… |
— |
| 2025-10-14 |
Insertion of Sensitive 2FA Information in logs and debug command
CVSSv3 Score:
2.6
An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attack… |
— |
| 2026-06-03 |
Linux Kernel vulnerability Dirty Frag
CVSSv3 Score:
7.9
Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag… |
CVE-2026-43284 CVE-2026-43500 |
| 2025-11-18 |
Trusted hosts bypass via SSH
CVSSv3 Score:
1.8
An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an … |
— |
| 2025-03-11 |
Pre-authentication Denial of Service attack in OpenSSH - CVE-2025-26466
CVSSv3 Score:
5.9
CVE-2025-26466A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pon… |
CVE-2025-26466 |
| 2026-05-13 |
Linux Kernel Vulnerability copy.fail - CVE-2026-31431
CVSSv3 Score:
7.8
CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Rev… |
CVE-2026-31431 |
| 2026-05-12 |
Arbitrary log file read in administrative interface
CVSSv3 Score:
4.0
An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-8… |
— |
| 2026-05-12 |
Command injection in CLI
CVSSv3 Score:
6.1
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerabilit… |
— |
| 2026-05-12 |
DoS due to unsafe function in signal handler
CVSSv3 Score:
5.2
A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may… |
— |
| 2026-05-12 |
Hardcoded Encryption Key Used for VPN Saved Passwords
CVSSv3 Score:
2.1
A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decr… |
— |
| 2026-05-12 |
Improper access control on API endpoints
CVSSv3 Score:
9.1
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated atta… |
— |
| 2026-05-12 |
Incorrect global authorization
CVSSv3 Score:
9.1
A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS … |
— |
| 2026-05-12 |
OS command injection in CLI
CVSSv3 Score:
6.5
An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated a… |
— |
| 2026-05-12 |
OTP Disclosure via Exported TokenContentProvider
CVSSv3 Score:
5.0
An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applic… |
— |
| 2026-05-12 |
Out-of-bounds access in CAPWAP daemon
CVSSv3 Score:
8.3
An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling … |
— |
最終取得: 2026-07-16 07:40(キャッシュ 30分)
| 公開日 | アドバイザリ | CVE |
|---|---|---|
| 2026-07-16 |
Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD… |
CVE-2026-20182 CVE-2026-20127 CVE-2026-20245 |
| 2026-07-16 |
Cisco Advance Notification for Publication of July 15, 2026, Security Advisories
On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:
Cisco Security … |
CVE-2026-20150 CVE-2026-20153 CVE-2026-20156 CVE-2026-20157 ほか 3 件 |
| 2026-07-16 |
Cisco RoomOS Security Hardening Release: July 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a… |
CVE-2026-20150 CVE-2026-20153 CVE-2026-20156 CVE-2026-20157 ほか 2 件 |
| 2026-07-16 |
Cisco Identity Services Engine Path Traversal Vulnerability
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenti… |
CVE-2026-20146 |
| 2026-07-07 |
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a … |
CVE-2026-20181 CVE-2026-20190 |
| 2026-07-06 |
Cisco Catalyst Center Arbitrary File Read Vulnerability
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted… |
CVE-2026-20191 |
| 2026-07-03 |
ClamAV Vulnerabilities Affecting Cisco Products: July 2026
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanni… |
CVE-2026-20213 CVE-2026-20214 CVE-2026-20215 CVE-2026-20216 ほか 3 件 |
| 2026-07-02 |
Cisco Advance Notification for Publication of July 1, 2026, Security Advisories
On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:
Cisco Security A… |
CVE-2026-20191 CVE-2026-20216 CVE-2026-20213 CVE-2026-20214 ほか 4 件 |
| 2026-07-02 |
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management E… |
CVE-2026-20230 |
| 2026-06-25 |
Cisco Finesse Remote File Inclusion Vulnerability
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations int… |
CVE-2026-20175 |
| 2026-06-23 |
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisc… |
CVE-2026-20055 CVE-2026-20109 |
| 2026-06-18 |
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate pri… |
CVE-2026-20246 |
| 2026-06-18 |
Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, rem… |
CVE-2026-20220 |
| 2026-06-18 |
Cisco Webex App Open Redirect Vulnerability
A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect… |
CVE-2026-20178 |
| 2026-06-17 |
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN M… |
CVE-2026-20127 |
| 2026-06-17 |
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after … |
CVE-2026-20182 |
| 2026-06-16 |
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote atta… |
CVE-2026-20262 |
| 2026-06-04 |
Cisco Webex Meetings Cross-Site Scripting Vulnerability
A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to … |
CVE-2026-20233 |
| 2026-05-21 |
Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Ci… |
CVE-2026-20171 |
| 2026-05-21 |
Cisco Secure Workload Unauthorized API Access Vulnerability
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remot… |
CVE-2026-20223 |
| 2026-05-21 |
Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability
A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attac… |
CVE-2026-20199 |
| 2026-05-21 |
Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability
A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote att… |
CVE-2026-20206 |
| 2026-05-20 |
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (E… |
CVE-2025-20333 CVE-2025-20362 |
| 2026-05-15 |
Cisco Catalyst SD-WAN Manager Vulnerabilities
Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow a remote attacker to gain acc… |
CVE-2026-20209 CVE-2026-20210 CVE-2026-20224 |
| 2026-05-15 |
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory
Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Co… |
CVE-2026-20188 |
| 2026-05-07 |
Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities
Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code on or conduct serv… |
CVE-2026-20034 CVE-2026-20035 |
| 2026-05-07 |
Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability
A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker t… |
CVE-2026-20172 |
| 2026-05-07 |
Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms … |
CVE-2026-20193 CVE-2026-20195 |
| 2026-05-07 |
Cisco Prime Infrastructure Information Disclosure Vulnerability
A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote att… |
CVE-2026-20189 |
| 2026-05-07 |
Cisco Slido Insecure Direct Object Reference Vulnerability
A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile d… |
CVE-2026-20219 |
最終取得: 2026-07-16 07:40(キャッシュ 30分)
最終取得: 2026-07-16 07:40(キャッシュ 30分)
| 公開日 | アドバイザリ | CVE |
|---|---|---|
| 2026-07-07 |
Ivanti Sentry OS Command Injection Vulnerability
FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical deta… |
CVE-2026-10520 |
| 2026-07-06 |
Langflow Unauth RCE Attack
FortiGuard Labs has observed a significant uptick in attacks targeting Langflow, leveraging a recently discovered authentication b… |
— |
| 2026-06-19 |
HTTP/2 Bomb Denial-of-Service Vulnerability
Security researchers have disclosed a new denial-of-service (DoS) attack technique dubbed HTTP/2 Bomb, tracked as CVE-2026-49975, … |
CVE-2026-49975 |
| 2026-06-11 |
Palo Alto Networks PAN-OS GlobalProtect Auth Bypass
Attackers are actively exploiting a PAN-OS GlobalProtect authentication bypass vulnerability to gain unauthorized VPN access to ex… |
CVE-2026-0257 |
| 2026-04-27 |
Cisco ASA and FTD Firewall RCE
Critical zero-day vulnerabilities affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Thre… |
— |
| 2026-04-06 |
SmarterTools SmarterMail RCE
An actively targeted vulnerability has been identified in SmarterTools SmarterMail, tracked as CVE-2025-52691, with a CVSS score o… |
CVE-2025-52691 |
| 2026-04-02 |
React2Shell Remote Code Execution
React2Shell is a critical unauthenticated remote code execution (RCE) vulnerability affecting React Server Components (RSC) and fr… |
— |
| 2026-03-31 |
Iran-linked Cyber Attacks
This report provides an overview of ongoing Iran-linked cyber operations, highlighting activity attributed to state-aligned proxie… |
— |
| 2026-03-19 |
Interlock Ransomware Attack
An active Interlock ransomware campaign is exploiting a critical vulnerability (CVE-2026-20131) in Cisco Secure Firewall Managemen… |
CVE-2026-20131 |
| 2026-03-10 |
Outbreak Alert- Annual Report 2025
In 2025, the FortiGuard Labs team processed and blocked 3.8 trillion vulnerability exploitation attempts, preventing 2.71 billion … |
— |
| 2026-02-03 |
Versa Concerto SD-WAN Authentication Bypass
Multiple critical security vulnerabilities in the Versa Concerto network security and SD-WAN orchestration platform. When chained,… |
— |
| 2025-12-02 |
UNC1549 Critical Infrastructure Espionage Attack
A suspected Iran-linked espionage group tracked as UNC1549 is actively targeting aerospace, defense, and telecommunications organi… |
— |
| 2025-11-13 |
Akira Ransomware
FortiGuard Labs continue to observe detections in the wild related to the Akira ransomware group. According to the new report by C… |
— |
| 2025-10-08 |
Oracle E-Business Suite RCE Zero-day
Actively exploited as a zero-day in data theft and extortion campaigns, with activity linked to the Cl0p ransomware group. Success… |
— |
| 2025-10-07 |
Fortra GoAnywhere MFT Attack
A critical deserialization vulnerability in GoAnywhere MFT’s License Servlet (CVSS 10.0) is actively being exploited in the wild. … |
— |
| 2025-09-12 |
ShadowSilk Data Exfiltration Attack
FortiGuard Labs’ network telemetry has observed active exploitation of known vulnerabilities in Drupal Core and the WP-Automatic W… |
— |
| 2025-08-06 |
Citrix Bleed 2
FortiGuard Labs has observed a sharp increase in exploitation attempts targeting the 'Citrix Bleed 2' vulnerability since July 28,… |
— |
| 2025-07-31 |
Microsoft SharePoint Zero-day Attack
FortiGuard Labs has detected and successfully blocked hundreds of exploitation attempts targeting a newly discovered zero-day vuln… |
— |
| 2025-07-18 |
SonicWall Secure Mobile Access Attack
A campaign targeting SonicWall SMA 100 series appliances is currently under active exploitation, leveraging both known vulnerabili… |
— |
| 2025-06-17 |
TBK DVRs Botnet Attack
Threat Actors are actively exploiting CVE-2024-3721, a command injection vulnerability in TBK DVR devices (Digital Video Recorders… |
CVE-2024-3721 |
最終取得: 2026-07-16 07:40(キャッシュ 30分)
| 公開日 | アドバイザリ | CVE |
|---|---|---|
| 2026-07-16 |
FortiADCManager 8.0.1
FortiADCManager 8.0.1 B0015 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-15 |
FortiSwitch 7.6.8
FortiSwitch 7.6.8 B1164 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-15 |
FortiWeb 8.0.6
FortiWeb 8.0.6 B0116 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-14 |
FortiDeceptor 6.3.0
FortiDeceptor 6.3.0 B0465 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-10 |
FortiMail 7.4.7
FortiMail 7.4.7 B0625 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-07 |
FortiVoice 8.0.0
FortiVoice 8.0.0 B0114 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-07 |
FortiPAM 1.9.1
FortiPAM 1.9.1 B1758 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-04 |
FortiPAM 1.8.4
FortiPAM 1.8.4 B1704 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-03 |
FortiAnalyzer-BigData 7.4.6
FortiAnalyzer-BigData 7.4.6 B1005 and release notes are available for download from the Support site : https://support.fortinet.co… |
— |
| 2026-07-03 |
FortiClient 8.0.0
FortiClient 8.0.0 B0103 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-03 |
FortiClientEMS 8.0.0
FortiClientEMS 8.0.0 B0121 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-03 |
FortiClientLinux 8.0.0
FortiClientLinux 8.0.0 B0055 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-03 |
FortiClientMac 8.0.0
FortiClientMac 8.0.0 B0078 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-02 |
FortiSwitch 7.6.7
FortiSwitch 7.6.7 B1163 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-01 |
FortiRecorder 7.6.0
FortiRecorder 7.6.0 B0382 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-07-01 |
FortiFone 7.2.3
FortiFone 7.2.3 B0273 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-30 |
FortiWeb 7.4.13
FortiWeb 7.4.13 B0727 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-26 |
FortiSwitchAXChassis 1.1.1
FortiSwitchAXChassis 1.1.1 B0132 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-23 |
FortiExtender 8.0.0
FortiExtender 8.0.0 B0026 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-23 |
FortiSOAR 8.0.0
FortiSOAR 8.0.0 B6034 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-20 |
FortiAP 8.0.0
FortiAP 8.0.0 B0033 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-19 |
FortiSandbox 4.4.6-CC b4532
FortiSandbox 4.4.6-CC b4532 and readme are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-18 |
FortiWeb 7.6.9
FortiWeb 7.6.9 B1133 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-12 |
FortiTester 7.6.2
FortiTester 7.6.2 B1292 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-12 |
FortiSwitchOS 7.6.1-FIPS-CC b8073-FIPS-CC-76-01
FortiSwitchOS 7.6.1-FIPS-CC b8073-FIPS-CC-76-01 and readme are available for download from the Support site : https://support.fort… |
— |
| 2026-06-12 |
FortiAP 7.4.5-FIPS-CC b4349-FIPS-CC-74-03
FortiAP 7.4.5-FIPS-CC b4349-FIPS-CC-74-03 and readme are available for download from the Support site : https://support.fortinet.c… |
— |
| 2026-06-12 |
FortiAP 7.4.5-FIPS-CC b4405-FIPS-CC-74-03
FortiAP 7.4.5-FIPS-CC b4405-FIPS-CC-74-03 and readme are available for download from the Support site : https://support.fortinet.c… |
— |
| 2026-06-11 |
FortiSandbox 5.2.0
FortiSandbox 5.2.0 B0290 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-10 |
FortiPAM 1.8.3
FortiPAM 1.8.3 B1702 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
| 2026-06-06 |
FortiDeceptor 6.2.2
FortiDeceptor 6.2.2 B0284 and release notes are available for download from the Support site : https://support.fortinet.com |
— |
WP-Cronで1日2回自動巡回(「再取得」で即時チェック)。タブの数字は直近7日間に変更があった対象数。
取得に失敗しました(HTTP 403)。URLが恒久的に取得不能な場合は監視対象から外してください。
コピーしました
