← RECON トップへ戻る ・ 記事一覧

CISA KEV速報 — 2026-09-22に4件追加

2026-09-22T00:00:00+09:00

CISA(米サイバーセキュリティ・インフラセキュリティ庁)のKnown Exploited Vulnerabilities(KEV)カタログに、2026-09-22付けで4件のCVEが新規追加された。KEVは実際の悪用が確認された脆弱性のみを掲載するリストであり、追加された時点で攻撃者による悪用が現に進行している可能性が高い。


CVE-2026-85102 — Check Point Multiple Products

脆弱性名: Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

項目 内容
ベンダー/製品 Check Point / Multiple Products
対応期限(CISA) 2026-09-25
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-85102

CVE-2026-93952 — Arista VeloCloud Orchestrator

脆弱性名: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

項目 内容
ベンダー/製品 Arista / VeloCloud Orchestrator
対応期限(CISA) 2026-09-25
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-93952

CVE-2026-93616 — Check Point Multiple Products

脆弱性名: Check Point Multiple Products Path Traversal Vulnerability

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

項目 内容
ベンダー/製品 Check Point / Multiple Products
対応期限(CISA) 2026-09-25
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-93616

CVE-2026-94127 — F5 BIG-IP APM

脆弱性名: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

項目 内容
ベンダー/製品 F5 / BIG-IP APM
対応期限(CISA) 2026-09-25
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-94127

※本記事はCISA KEVの公開データをもとに機械的に生成している。対応要否は各組織の環境に応じて判断すること。