2026年9月21日〜2026年9月27日にJPCERT/CC(日本)、IPA(日本)、CISA(米国)、NCSC(英国)が公表したサイバーセキュリティの注意喚起・脆弱性情報15件を、日本語の見出しでまとめています。
注意喚起: F5 BIG-IP Access Policy Managerにおけるヒープベースのバッファオーバーフローの脆弱性(CVE-2026-94127)に関する注意喚起 (公開)
JPCERT/CC(日本) ・ 2026年9月24日
NetScaler ADCおよびNetScaler Gatewayの脆弱性について(CVE-2026-88771、CVE-2026-88772等)
IPA(日本) ・ 2026年9月27日
悪用確認(KEV): Citrix NetScaler — メモリ範囲外の操作(バッファ処理の不備) (CVE-2026-88772)
KEV追加: Citrix NetScaler — Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2026-88772)
CISA(米国) ・ 2026年9月27日
悪用確認(KEV): Citrix NetScaler — 入力値検証の不備 (CVE-2026-88771)
KEV追加: Citrix NetScaler — Citrix NetScaler Improper Input Validation Vulnerability (CVE-2026-88771)
CISA(米国) ・ 2026年9月27日
悪用確認(KEV): MikroTik RouterOS — 処理手順の制御不備 (CVE-2026-67279)
KEV追加: MikroTik RouterOS — Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability (CVE-2026-67279)
CISA(米国) ・ 2026年9月25日
悪用確認(KEV): Microsoft SharePoint — コードインジェクション (CVE-2026-65660)
KEV追加: Microsoft SharePoint — Microsoft SharePoint Code Injection Vulnerability (CVE-2026-65660)
CISA(米国) ・ 2026年9月25日
悪用確認(KEV): WordPress Core — リモートファイルインクルージョン (CVE-2026-87902)
KEV追加: WordPress Core — WordPress Core Remote File Inclusion Vulnerability (CVE-2026-87902)
CISA(米国) ・ 2026年9月25日
悪用確認(KEV): WSO2 Multiple Products — パストラバーサル (CVE-2026-5430)
KEV追加: WSO2 Multiple Products — WSO2 Multiple Products Path Traversal Vulnerability (CVE-2026-5430)
CISA(米国) ・ 2026年9月24日
悪用確認(KEV): Adobe Commerce and Magento — 認可の不備 (CVE-2026-71362)
KEV追加: Adobe Commerce and Magento — Adobe Commerce and Magento Incorrect Authorization Vulnerability (CVE-2026-71362)
CISA(米国) ・ 2026年9月24日
悪用確認(KEV): Arista VeloCloud Orchestrator — 入力値検証の不備 (CVE-2026-93952)
KEV追加: Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator Improper Input Validation Vulnerability (CVE-2026-93952)
CISA(米国) ・ 2026年9月22日
悪用確認(KEV): F5 BIG-IP APM — ヒープバッファオーバーフロー (CVE-2026-94127)
KEV追加: F5 BIG-IP APM — F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability (CVE-2026-94127)
CISA(米国) ・ 2026年9月22日
悪用確認(KEV): Check Point Multiple Products — パストラバーサル (CVE-2026-93616)
KEV追加: Check Point Multiple Products — Check Point Multiple Products Path Traversal Vulnerability (CVE-2026-93616)
CISA(米国) ・ 2026年9月22日
悪用確認(KEV): Check Point Multiple Products — 証明書検証の不備 (CVE-2026-85102)
KEV追加: Check Point Multiple Products — Check Point Multiple Products Improper Certificate Validation Vulnerability (CVE-2026-85102)
CISA(米国) ・ 2026年9月22日
悪用確認(KEV): Zyxel GS1900 Series Switches — スタックバッファオーバーフロー (CVE-2026-7273)
KEV追加: Zyxel GS1900 Series Switches — Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability (CVE-2026-7273)
CISA(米国) ・ 2026年9月21日
One does not simply defend agentically
NCSC(英国) ・ 2026年9月21日