FORSMILE
JA

Tech Blog

Practical articles on AI, online safety, and security (60 articles)

AllAIネット安全セキュリティJavaScriptCSSWordPressVUETwigSymfonySmartyNUXTAMP開発記事
SECURITY ALERT
セキュリティ2026/08/26

[URGENT] Oracle HTTP Server / WebLogic Proxy Plug-in CVE-2026-21962: Apply the January 2026 CPU Now — Unauthenticated Data Tampering

CISA added this flaw to the KEV catalog on August 24, 2026 with a remediation deadline of August 27. Exploitable over the network without authentication and scored 10.0 under CVSS 3.1, here are the affected versions, the patch to apply, and Oracle's own stance on workarounds.

Read More →
セキュリティ2026/09/16

JetFormBuilder CVE-2026-12793: Update to 3.6.5.3 — Unauthenticated Admin Account Creation

JetFormBuilder for WordPress (about 80,000 active installs) lets an unauthenticated attacker create an administrator account. Wordfence scores it 9.8 CRITICAL on CVSS v3.1. This CVE itself is fixed in 3.6.2.1, but five more CVEs landed in September, so clearing all six takes 3.6.5.2 or later.

Read More →
セキュリティ2026/09/15

Cisco Secure Email Gateway CVE-2026-76461: Patch to 16.5.0-780 — A Single Email Grants Root

A crafted email is enough to run commands as root on Cisco Secure Email Gateway, with no authentication. Cisco scores it 9.8 CRITICAL on CVSS v3.1 and states it became aware of active exploitation in September 2026. There are no workarounds.

Read More →
セキュリティ2026/09/14

GitLab CVE-2026-85706: Patch to 19.1.8/19.2.6/19.3.2 — Unauthenticated Arbitrary File Read, Already Exploited

Self-managed GitLab has a flaw that lets an unauthenticated attacker read arbitrary files from the server. CVE-2026-85706 is scored 10.0 CRITICAL on CVSS v3.1 by GitLab. CISA added it to the Known Exploited Vulnerabilities catalog on 11 September 2026. Fixed in 19.1.8, 19.2.6 and 19.3.2.

Read More →
セキュリティ2026/09/11

miniOrange 2FA CVE-2026-77770: Update to 6.3.1 — Unauthenticated Option Deletion Locks Out Every Admin

A flaw in the WordPress plugin miniOrange 2FA lets any unauthenticated visitor delete arbitrary site options. WPScan scores it 10.0 CRITICAL on CVSS v3.1. Fixed in 6.3.1 (free) and 19.3 (Pro), with a proof of concept scheduled for public release on 8 October 2026.

Read More →
セキュリティ2026/09/10

Chrome CVE-2026-87491: Update to 153.0.8010.36 — V8 Zero-Day Exploited in the Wild

Google shipped Chrome 153 (153.0.8010.36) to fix CVE-2026-87491, an out-of-bounds write in V8. Google rates it Medium, but its own release notes confirm an exploit exists in the wild, CISA set a 23 September 2026 deadline, and other Chromium browsers such as Edge and Opera are in scope too.

Read More →
セキュリティ2026/09/09

Google ADK for Python CVE-2026-79696: Update to 2.7.0 — Unauthenticated Code Execution in adk web

Google's Agent Development Kit for Python, google-adk 2.0.0 through 2.6.0, has a CVSS 10.0 code injection. A crafted test session replay against adk web on a host with pytest installed gives an unauthenticated attacker code execution. Fixed in 2.7.0 — and we verified in the source that 2.6.1 through 2.6.3 are unpatched too.

Read More →
セキュリティ2026/09/08

Frontend Admin by DynamiApps CVE-2026-75816: Update to 3.29.13 — Unauthenticated Admin Takeover

The WordPress plugin Frontend Admin by DynamiApps is vulnerable to a CVSS 9.8 authentication bypass in all versions up to and including 3.29.12. An unauthenticated attacker can overwrite an administrator's email address and take the account over through the password reset flow. Version 3.29.13 shipped on 25 August 2026. Around 9,000 active installs.

Read More →
セキュリティ2026/09/07

Oracle HTTP Server and WebLogic Proxy Plug-in: Component and Patch Checklist

Inventory the web tier separately from WebLogic Server. Record Oracle Home patch history, the configured plug-in path and post-change checks in a handoff template.

Read More →
セキュリティ2026/09/04

MapLibre GL JS CVE-2026-85061: Update to 6.4.1 — Zero-Click XSS via Map Attribution

MapLibre GL JS 6.4.0 and earlier carry a CVSS 10.0 XSS. The sanitizer skips one dangerous attribute out of every adjacent pair, and the surviving handler fires the moment the map renders its attribution. Update the maplibre-gl npm package to 6.4.1 or later.

Read More →
セキュリティ2026/09/03

LiteLLM CVE-2026-59822: Update to 1.84.0 — Exploited MCP Auth Bypass

CISA added LiteLLM's MCP auth bypass and Starlette's missing Host header validation to its KEV catalog of actively exploited flaws on September 2, 2026. Update LiteLLM to 1.84.0, Starlette to 1.0.1.

Read More →
セキュリティ2026/09/02

Amelia for WordPress CVE-2026-9055: Update to 9.6.3 or Later — Unauthenticated Admin Takeover

Amelia Premium 8.0 through 9.6.2 lets an unauthenticated attacker overwrite an administrator's password and take over the account (CVE-2026-9055, CVSS v3.1 9.8 CRITICAL). The fix is 9.6.3; the current release is 9.8.1. Check your version number first — the free edition uses a different version series.

Read More →
セキュリティ2026/09/01

PaperCut NG/MF CVE-2026-81578: Patch Now, Exploited in Wild

PaperCut NG/MF, CVE-2026-81578 and CVE-2026-82078: restrict internet access to the admin interface now, then apply Emergency Patch Release 3. The two are being chained in real attacks and CISA added both to its Known Exploited Vulnerabilities catalog on 2026-08-31. Version numbers will not tell you whether you are safe.

Read More →
セキュリティ2026/08/31

Nodemailer CVE-2026-82854: Update to 8.0.4+ — SMTP Injection via envelope.size

An SMTP command injection in Nodemailer via envelope.size. It does not occur under default settings, and scoring is split between LOW and CRITICAL. Here is how to tell whether you are actually affected.

Read More →
セキュリティ2026/08/28

JFrog Artifactory CVE-2026-66384: Upgrade to 7.146.35 or 7.161.16 — Exploited Image Cache Poisoning

An authenticated user can write outside the intended Docker cache path, so a forged image gets cached under a trusted name. The CVSS score is only 5.3, but it was exploited in the wild and is now in CISA's KEV catalog.

Read More →
セキュリティ2026/08/27

[URGENT] Gitea CVE-2026-60004: Upgrade to 1.27.1 Now — Actively Exploited RCE

Gitea 1.17 through 1.27.0 lets an attacker plant a live Git hook through the diffpatch API and run commands as the Gitea service account. CISA added it to KEV on August 25 with an August 28 due date. Affected versions, real preconditions, and checks.

Read More →
セキュリティ2026/08/16

Kubernetes ingress-nginx CVE-2026-4342: Exact Preconditions and Fixed Versions

CVE-2026-4342 starts with a low-privileged user who can create or modify Ingress annotations. This correction lists the exact affected and fixed versions and resulting impact.

Read More →
セキュリティ2026/08/14

Metabase CVE-2026-72898: Patch an Actively Exploited SQL Injection

An unauthenticated SQL injection can lead to Metabase administrator access. Update to the fixed release for the deployed branch and perform the vendor's compromise checks.

Read More →
セキュリティ2026/08/13

Correction: WordPress 7.0.2 Security Release, Affected CVEs, and Update Steps

The previous CVE identifier and WordPress 7.0.4 claims were incorrect. This correction uses the official 7.0.2 release and CVE-2026-60137/63030 details.

Read More →
セキュリティ2026/08/12

Correction: SharePoint CVE-2026-55040 and CVE-2026-63520

Microsoft lists a Critical security bypass and a High-severity RCE, but not confirmed exploitation at publication. Apply the product-specific updates promptly.

Read More →
セキュリティ2026/08/03

N-able N-central CVE-2026-18577: Update to Hotfix 2 (2026.3.1.10)

Hotfix 1 has been superseded by additional mitigation. On-premises deployments should install 2026.3.1.10 and investigate for compromise because exploitation has been observed.

Read More →
セキュリティ2026/08/02

Correction: Linux Kernel CVE-2026-64535 and Related Network Bugs

The three NVMe/TCP, SMC, and SCTP issues should not be described collectively as CVSS 9.8 remote RCEs. This correction uses the official Linux CVE announcements.

Read More →
セキュリティ2026/08/01

[URGENT] WordPress Plugin ARVE CVE-2026-18072: Delete Immediately — Risk of Admin Privilege Escalation via Authentication Bypass

An urgent backdoor, CVE-2026-18072, has been discovered in WordPress plugin 'Advanced Responsive Video Embedder (ARVE)' version 10.8.7. Please delete the affected plugin immediately.

Read More →
セキュリティ2026/07/31

[Alert] This Week's Essential Security Settings Checklist: Hardening Web Services for Developers

A security settings checklist that Web service developers should integrate into their weekly routine. Review it now and maintain secure operations.

Read More →
セキュリティ2026/07/29

[URGENT] Arista VeloCloud Orchestrator CVE-2026-16812: Install Fixed Builds — Critical Unauthenticated On-Premises Exposure

CVE-2026-16812 lets an unauthenticated remote attacker reach privileged internal functionality in VeloCloud Orchestrator On-Prem. Arista rates it CVSS v3.1 10.0. Install the fixed build for your branch immediately.

Read More →
セキュリティ2026/07/27

[URGENT] Microsoft .NET CVE-2026-47304: Apply Security Update — Severe Impact on Confidentiality, Integrity, and Availability

An urgent vulnerability (CVE-2026-47304) affecting Microsoft .NET and Visual Studio has been discovered, allowing unauthenticated attackers to bypass security features. Immediate update to a patched version is mandatory.

Read More →
セキュリティ2026/07/26

【URGENT】OpenRemote CVE-2026-66013: Update Resolves Authentication Bypass – Risk of IoT Console Hijack

An authentication bypass vulnerability (CVE-2026-66013) has been discovered in OpenRemote versions prior to 1.26.2. Unauthorized attackers could update console assets and hijack notifications, necessitating an immediate update to the patched version.

Read More →
セキュリティ2026/07/24

[Baseline] A Security Configuration Checklist for Continuous Operations

A practical recurring checklist for patching, MFA, least privilege, backups, and logging. Prioritize each control for your assets and risk instead of relying on a daily news cycle.

Read More →
セキュリティ2026/07/18

[URGENT] WordPress CVE-2026-63030: REST API Vulnerability and Fixed Releases

REST API batch-route confusion and SQL injection can lead to remote code execution. Check the applicable fixed release: 6.9.5 for the 6.9 branch or 7.0.2 for 7.0.

Read More →
セキュリティ2026/07/17

[URGENT] SharePoint Server CVE-2026-56164 and CVE-2026-58644: Apply the CVE-Specific Updates

Separate SharePoint authentication-bypass privilege escalation CVE-2026-56164 from deserialization RCE CVE-2026-58644 and install each fixed build. Microsoft's scores are 5.3 MEDIUM and 9.8 CRITICAL.

Read More →
セキュリティ2026/07/16

[URGENT] NGINX CVE-2026-42533: Update to 1.30.4 or 1.31.3 — DoS and Conditional Code Execution

A heap buffer overflow affects NGINX map regular-expression processing. It can restart workers and cause DoS; code execution requires ASLR to be disabled or bypassed. Install a fixed release.

Read More →
セキュリティ2026/07/13

[ADVISORY] Cisco IOS CVE-2008-4128: Disable or Restrict HTTP Administration and Replace EOL Hardware

Cisco IOS 12.4 on the Cisco 871 has CSRF flaws that abuse an authenticated administrator session. Disable or restrict HTTP administration and migrate to supported hardware.

Read More →
セキュリティ2026/07/12

[Correction] Linux KVM CVE-2026-53359: Shadow-Paging Use-After-Free and Host Updates

CVE-2026-53359 affects x86 KVM shadow paging and can cross the guest-to-host security boundary. Check the virtualization host's patch status. The earlier success-rate claims have been withdrawn.

Read More →
セキュリティ2026/07/10

[Correction] Linux CVE-2026-43499: Local rtmutex Privilege Escalation and Kernel Updates

A flaw in Linux rtmutex handling can lead to use-after-free through local futex operations. Install the kernel vendor's fixed package and verify that the fix is running.

Read More →
セキュリティ2026/07/08

[URGENT] Severe Path Traversal Vulnerability in Adobe ColdFusion (CVE-2026-48282) Actively Exploited - Patch Immediately

A critical path traversal vulnerability, CVE-2026-48282, in Adobe ColdFusion is being actively exploited. With a CVSS score of 10.0, immediate patching for this vulnerability is imperative.

Read More →
セキュリティ2026/07/07

[URGENT] NetScaler CVE-2026-8451: Update Affected Builds — Memory Over-read in SAML IdP Configurations

NetScaler ADC/Gateway configured as a SAML IdP has an unauthenticated memory over-read flaw. The CNA rates it CVSS v4.0 8.8 HIGH. Update the affected build.

Read More →
セキュリティ2026/07/02

[URGENT] Severe RCE Vulnerability (CVE-2026-45659) Discovered in Microsoft SharePoint Server, Added to CISA KEV

A severe authenticated RCE vulnerability, 'CVE-2026-45659,' has been discovered in Microsoft SharePoint Server and added to the CISA KEV catalog. It allows code execution even by low-privileged users, necessitating immediate patch application.

Read More →
セキュリティ2026/07/01

[URGENT] WordPress Offload, AI & Optimize with Cloudflare Images CVE-2026-9860: Install a Fixed Release

This third-party WordPress plugin allows an authenticated Author-level user to execute code. Versions through 1.10.2 are affected; it is not a Cloudflare product.

Read More →
セキュリティ2026/06/30

[URGENT] Adobe ColdFusion CVE-2026-48276: Update to 2025 Update 10 or 2023 Update 21

An unrestricted upload of a dangerous file type can lead to code execution without authentication or user interaction. Install the fixed releases in Adobe bulletin APSB26-68.

Read More →
セキュリティ2026/06/29

[URGENT] Linux Kernel CVE-2026-46331: Update Stable Kernels — Local tc pedit Privilege Escalation

Partial copy-on-write handling in tc pedit can corrupt page-cache data. This is a local CAP_NET_ADMIN attack, not remote RCE. Install a fixed distribution kernel.

Read More →
セキュリティ2026/06/27

[URGENT] Ultimate Member CVE-2026-7761: Update — Account Takeover by Contributor-Level Users

Ultimate Member 2.11.4 and earlier can expose password-reset links to an authenticated Contributor-level attacker, enabling takeover of accounts including administrators.

Read More →
セキュリティ2026/06/23

[URGENT] High Alert for Deno Network Restriction Bypass Vulnerability (CVE-2026-49859)! Risk of Unauthorized Access to Internal Networks

A critical vulnerability has been discovered in the Deno runtime that allows bypassing the --deny-net rule, enabling access to internal networks. Immediate update to version 2.8.1 or later is required.

Read More →
セキュリティ2026/06/23

[URGENT] ShapedPlugin Supply-Chain Compromise: Verify Fixed Releases for Three Products — CVE-2026-10735/49777

A compromised update server distributed malicious code to three Pro plugins. Install each product's fixed release, rotate credentials, and investigate the site for persistence.

Read More →
セキュリティ2026/06/18

[URGENT] Joomla JCE CVE-2026-48907: Install the Fixed Release or Official Patch — Unauthenticated RCE

JCE 1.0.0 through 2.9.99.4 can allow unauthenticated creation of editor profiles followed by PHP upload and execution. Apply JCE's fixed release or official legacy patch.

Read More →
セキュリティ2026/06/16

[URGENT] Severe Unauthenticated SQL Injection Vulnerability in Popular WordPress Plugin 'eCommerce Product Catalog'

A severe unauthenticated SQL injection vulnerability has been discovered in WordPress plugin 'eCommerce Product Catalog' versions 3.5.5 and below, allowing database manipulation without authentication. Immediate update is mandatory.

Read More →
セキュリティ2026/06/15

[URGENT] Remote Code Execution Vulnerability in JavaScript Engine of PDF Processing Applications (CVE-2026-12057)

A critical vulnerability has been discovered in applications that process JavaScript embedded in PDF files. Maliciously crafted PDFs could lead to arbitrary code execution.

Read More →
セキュリティ2026/06/14

[URGENT] Authentication Bypass Vulnerability in PHP Applications! Risk of Administrator Privilege Takeover (CVE-2026-12183)

An authentication bypass vulnerability has been discovered in the PHP application of Nefteprodukttekhnika BUK TS-G. This could allow a remote, unauthenticated attacker to seize administrator privileges and manipulate the system.

Read More →
セキュリティ2026/06/13

[URGENT] Zero-Day RCE Vulnerability in Oracle PeopleSoft: Over 100 Organizations, Including Universities, Targeted

A severe vulnerability (CVSS 9.8) allowing unauthenticated remote code execution has been discovered in Oracle PeopleSoft Enterprise PeopleTools, and numerous organizations have been compromised by zero-day attacks. Immediate patching and access restrictions are required.

Read More →
セキュリティ2026/06/12

[URGENT] Unauthenticated OS Command Injection Vulnerability (CVE-2026-10520) Discovered in Ivanti Sentry - Apply Patch Immediately!

An unauthenticated OS command injection vulnerability in Ivanti Sentry has been urgently disclosed. Rated with a CVSS score of 10.0, active exploitation has already been confirmed. Immediate patch application and access restrictions are mandatory.

Read More →
セキュリティ2026/06/11

[URGENT] Authentication Bypass RCE Vulnerability in WordPress Plugin 'UpdraftPlus' Puts Over 3 Million Sites at Risk, Active Attacks Confirmed

A vulnerability in WordPress's popular backup plugin 'UpdraftPlus' is being actively exploited, potentially allowing unauthenticated attackers to gain administrator privileges and execute remote code.

Read More →
セキュリティ2026/06/10

[URGENT] Check Point VPN CVE-2026-50751: Apply the sk185033 Hotfix — IKEv1 Authentication Bypass

A certificate-validation logic flaw in deprecated IKEv1 can let an unauthenticated attacker establish Remote Access VPN without a valid user password.

Read More →
セキュリティ2026/06/09

[URGENT] Chrome V8 CVE-2026-11645: Update to 149.0.7827.103 or Later

V8 in Chrome before 149.0.7827.103 has an out-of-bounds read/write that can execute code inside the sandbox through crafted HTML. Install Google's fixed release.

Read More →
セキュリティ2026/06/08

[URGENT] Denial-of-Service Vulnerability (CVE-2026-49975) Discovered in Apache HTTP Server's mod_http, Urgent Update Recommended

A critical denial-of-service (DoS) vulnerability, CVE-2026-49975, has been disclosed in the mod_http module of Apache HTTP Server. Versions 2.4.17 through 2.4.67 are affected, and a prompt update is recommended.

Read More →
セキュリティ2026/06/06

[URGENT] HTTP/2 Bomb CVE-2026-49975: Update NGINX to 1.29.8 or Apache to 2.4.68 — Remote DoS

CVE-2026-49975 combines HTTP/2 HPACK compression with flow-control stalling to consume large server resources from limited traffic. It is rated CVSS v3.1 7.5 HIGH. Apply the product-specific fix or official mitigation.

Read More →
セキュリティ2026/06/05

[URGENT] Everest Forms Pro CVE-2026-3300 and PHP CVE-2025-14179: Install Each Fixed Release

Unauthenticated RCE in Everest Forms Pro and SQL injection in PDO Firebird are separate issues. Their authoritative scores are CVSS v3.1 9.8 and CVSS v4.0 7.4.

Read More →
セキュリティ2026/06/04

[URGENT] Mirasvit Cache Warmer CVE-2026-45247: Update to 1.11.12 — Unauthenticated RCE

Full Page Cache Warmer for Magento 2 before 1.11.12 unsafely deserializes the CacheWarmer cookie, allowing unauthenticated RCE through available gadget chains.

Read More →
セキュリティ2026/06/03

[URGENT] WP Maps Pro CVE-2026-8732: Install a Confirmed Fixed Release — Unauthenticated Administrator Creation

WP Maps Pro 6.1.0 and earlier exposes a nonce and temporary-access handler that can create an administrator without authentication. Update to version 6.1.1 or later.

Read More →
セキュリティ2026/06/02

[URGENT] WP Maps Pro CVE-2026-8732: Install a Confirmed Fixed Release — Unauthenticated Administrator Creation

WP Maps Pro 6.1.0 and earlier exposes a nonce and temporary-access handler that can create an administrator without authentication. Update to version 6.1.1 or later.

Read More →
セキュリティ2026/06/01

[URGENT] Plesk for Linux CVE-2026-44962: Update to 18.0.75.1 or 18.0.76.2

XPath injection in APS Application Catalog search can let a low-privileged authenticated user execute OS commands. The authoritative CVSS v3.1 score is 9.9, not 10.0.

Read More →
セキュリティ2026/05/31

[URGENT] Severe Authentication Bypass Vulnerability in Palo Alto Networks PAN-OS GlobalProtect, Immediate Action Required

A severe authentication bypass vulnerability (CVE-2026-0257) has been disclosed in Palo Alto Networks PAN-OS GlobalProtect, and active exploitation has been confirmed. Urgent patch application and mitigation measures are essential.

Read More →