← RECON トップへ戻る ・ 記事一覧

CISA KEV速報 — 2026-09-25に3件追加

2026-09-25T00:00:00+09:00

CISA(米サイバーセキュリティ・インフラセキュリティ庁)のKnown Exploited Vulnerabilities(KEV)カタログに、2026-09-25付けで3件のCVEが新規追加された。KEVは実際の悪用が確認された脆弱性のみを掲載するリストであり、追加された時点で攻撃者による悪用が現に進行している可能性が高い。


CVE-2026-65660 — Microsoft SharePoint

脆弱性名: Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

項目 内容
ベンダー/製品 Microsoft / SharePoint
対応期限(CISA) 2026-09-28
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-65660

CVE-2026-67279 — MikroTik RouterOS

脆弱性名: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

項目 内容
ベンダー/製品 MikroTik / RouterOS
対応期限(CISA) 2026-09-28
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-67279

CVE-2026-87902 — WordPress Core

脆弱性名: WordPress Core Remote File Inclusion Vulnerability

WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local .php file outside the active theme directories, leading to remote code execution.

項目 内容
ベンダー/製品 WordPress / Core
対応期限(CISA) 2026-09-28
ランサムウェア悪用 Unknown
詳細 NVD: CVE-2026-87902

※本記事はCISA KEVの公開データをもとに機械的に生成している。対応要否は各組織の環境に応じて判断すること。