CISA KEV速報 — 2026-09-25に3件追加
CISA(米サイバーセキュリティ・インフラセキュリティ庁)のKnown Exploited Vulnerabilities(KEV)カタログに、2026-09-25付けで3件のCVEが新規追加された。KEVは実際の悪用が確認された脆弱性のみを掲載するリストであり、追加された時点で攻撃者による悪用が現に進行している可能性が高い。
CVE-2026-65660 — Microsoft SharePoint
脆弱性名: Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | Microsoft / SharePoint |
| 対応期限(CISA) | 2026-09-28 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-65660 |
CVE-2026-67279 — MikroTik RouterOS
脆弱性名: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | MikroTik / RouterOS |
| 対応期限(CISA) | 2026-09-28 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-67279 |
CVE-2026-87902 — WordPress Core
脆弱性名: WordPress Core Remote File Inclusion Vulnerability
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local .php file outside the active theme directories, leading to remote code execution.
| 項目 | 内容 |
|---|---|
| ベンダー/製品 | WordPress / Core |
| 対応期限(CISA) | 2026-09-28 |
| ランサムウェア悪用 | Unknown |
| 詳細 | NVD: CVE-2026-87902 |
※本記事はCISA KEVの公開データをもとに機械的に生成している。対応要否は各組織の環境に応じて判断すること。