2026年9月14日〜2026年9月20日にJPCERT/CC(日本)、CISA(米国)、NCSC(英国)が公表したサイバーセキュリティの注意喚起・脆弱性情報12件を、日本語の見出しでまとめています。
注意喚起: Cisco Secure Email GatewayにおけるSQLインジェクションの脆弱性(CVE-2026-76461)に関する注意喚起 (公開)
JPCERT/CC(日本) ・ 2026年9月15日
悪用確認(KEV): Linux Kernel — 競合状態 (CVE-2025-39964)
KEV追加: Linux Kernel — Linux Kernel Race Condition Vulnerability (CVE-2025-39964)
CISA(米国) ・ 2026年9月18日
悪用確認(KEV): Linux Kernel — 境界外書き込み (CVE-2026-53266)
KEV追加: Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2026-53266)
CISA(米国) ・ 2026年9月18日
悪用確認(KEV): Linux Kernel — 例外条件のチェック不備 (CVE-2025-39682)
KEV追加: Linux Kernel — Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2025-39682)
CISA(米国) ・ 2026年9月18日
悪用確認(KEV): Google Pixel — 認可の不備 (CVE-2026-58704)
KEV追加: Google Pixel — Google Pixel Improper Authorization Vulnerability (CVE-2026-58704)
CISA(米国) ・ 2026年9月16日
悪用確認(KEV): Cisco Identity Services Engine — 特権APIの不適切な利用 (CVE-2026-76460)
KEV追加: Cisco Identity Services Engine — Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460)
CISA(米国) ・ 2026年9月16日
悪用確認(KEV): Acronis Backup — 既定の権限設定の不備 (CVE-2026-87886)
KEV追加: Acronis Backup — Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886)
CISA(米国) ・ 2026年9月16日
悪用確認(KEV): Cisco Secure Email Gateway — SQLインジェクション (CVE-2026-76461)
KEV追加: Cisco Secure Email Gateway — Cisco Secure Email Gateway SQL Injection Vulnerability (CVE-2026-76461)
CISA(米国) ・ 2026年9月14日
Adversary simulation: what you need to know
NCSC(英国) ・ 2026年9月17日
Cyber Adversary Simulation (CyAS): scheme documents now available
NCSC(英国) ・ 2026年9月17日
Iranian cyber targeting of dissidents, activists and journalists
NCSC(英国) ・ 2026年9月15日
英国と同盟国、イラン国家関与の攻撃者が反体制派らの標的に用いたスパイウェアを公表
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
NCSC(英国) ・ 2026年9月15日