CISA KEV速報 — 2026-09-24に2件追加
CISA(米サイバーセキュリティ・インフラセキュリティ庁)のKnown Exploited Vulnerabilities(KEV)カタログに、2026-09-24付けで2件のCVEが新規追加された。KEVは実際の悪用が確認された脆弱性のみを掲載するリストであり、追加された時点で攻撃者による悪用が現に進行している可能性が高い。
CVE-2026-5430 — WSO2 Multiple Products
脆弱性名: WSO2 Multiple Products Path Traversal Vulnerability
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | WSO2 / Multiple Products |
| 対応期限(CISA) | 2026-09-27 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-5430 |
CVE-2026-71362 — Adobe Commerce and Magento
脆弱性名: Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | Adobe / Commerce and Magento |
| 対応期限(CISA) | 2026-09-27 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-71362 |
※本記事はCISA KEVの公開データをもとに機械的に生成している。対応要否は各組織の環境に応じて判断すること。