🔥 この日の重要情報
2026-08-11 更新
B
今週中

Johnson ControlsのC-CURE 9000およびVictorアプリケーションサーバーに、リモートコード実行(RCE)につながる深刻な脆弱性

脆弱性🌐 英語ソース
🔢 CVECVE-2026-21655CVE-2026-34496
📅 2026-08-11📰 cisa
📌 一言でいうと
Johnson ControlsのC-CURE 9000およびVictorアプリケーションサーバーに、リモートコード実行(RCE)につながる深刻な脆弱性が発見されました。攻撃者がネットワークアクセス権を持っている場合、認証なしで任意のコードを実行したり、サーバーサイドリクエストフォージェリ(SSRF)を悪用したりすることが可能です。影響を受けるバージョンはC-CURE 9000 v3.10.1以下、Victor Application Server v4.10以下、Victor v7.0以下、およびVictor Web v7.1以下です。
🔍該当判定
  • Johnson Controls社の入退室管理システム「C-CURE 9000」を利用している
  • Johnson Controls社の「victor Application Server」を利用している
  • Johnson Controls社の「victor」または「victor Web」を利用している
上記いずれにも該当しない → 静観でOK
該当時の対応
影響を受ける製品のバージョンを確認し、ベンダーが提供する最新のアップデートまたはパッチを速やかに適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Johnson Controls C-CURE 9000 / Victor 脆弱性 (CVE-2026-21655他) 対応について

お疲れさまです。Johnson Controls製品の脆弱性に関する情報共有です。

■ 概要
C-CURE 9000およびVictorアプリケーションサーバーにおいて、リモートコード実行(RCE)が可能な深刻な脆弱性が報告されました。CVSS v3 スコアは 9.6 と非常に高く、認証なしの攻撃者がネットワーク経由で攻撃を行う可能性があります。

■ 影響範囲
- C-CURE 9000 <=v3.10.1
- Victor Application Server <=v4.10
- Victor <=v7.0
- Victor Web <=v7.1

■ 対応手順
1. 自社環境で利用している製品のバージョンを確認してください。
2. 該当する場合、ベンダーから提供される最新のアップデート(Update A等)を適用してください。

■ 参考情報
- CISA ICS Advisory ICSA-26-204-01

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Johnson Controls C-CURE 9000 / Victor Vulnerabilities (CVE-2026-21655 et al.)

Dear IT/Security Team,

We are sharing critical vulnerability information regarding Johnson Controls products.

■ Overview
Critical vulnerabilities have been discovered in C-CURE 9000 and Victor application servers, allowing for Remote Code Execution (RCE). With a CVSS v3 score of 9.6, unauthenticated attackers on adjacent networks could potentially execute arbitrary code.

■ Affected Scope
- C-CURE 9000 <=v3.10.1
- Victor Application Server <=v4.10
- Victor <=v7.0
- Victor Web <=v7.1

■ Mitigation Steps
1. Verify the versions of the products currently deployed in your environment.
2. If affected, immediately apply the latest updates (Update A or newer) provided by the vendor.

■ Reference
- CISA ICS Advisory ICSA-26-204-01

Priority: High
Deadline: Immediate
B
今週中

Microsoft SharePoint Serverのオンプレミス版において、認証なしでリモートコード実行(RCE)が可能な脆弱性の連鎖

脆弱性🌐 英語ソース
🖥️ 製品SharePoint
🔢 CVECVE-2026-55040CVE-2026-63520
📅 2026-08-11📰 hackernews
📌 一言でいうと
Microsoft SharePoint Serverのオンプレミス版において、認証なしでリモートコード実行(RCE)が可能な脆弱性の連鎖が発見されました。攻撃者はCVE-2026-55040を利用して任意のユーザー(管理者を含む)になりすまし、さらにCVE-2026-63520を組み合わせることでサーバー上でコードを実行できます。この脆弱性の発見にはAIエージェントが活用されており、SharePoint Server 2016, 2019, およびSubscription Editionが影響を受けます。
🔍該当判定
  • 自社で「SharePoint Server 2016」を運用している
  • 自社で「SharePoint Server 2019」を運用している
  • 自社で「SharePoint Server Subscription Edition」を運用している
上記いずれにも該当しない(SharePoint Onlineのみ利用、またはSharePointを未利用) → 静観でOK
該当時の対応
影響を受けるSharePoint Serverのバージョンを確認し、Microsoftが提供する最新のセキュリティ更新プログラムを速やかに適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Microsoft SharePoint Server 脆弱性 (CVE-2026-55040 / CVE-2026-63520) 対応について

お疲れさまです。SharePoint Serverにおける深刻な脆弱性の連鎖に関する情報共有です。

■ 概要
認証なしで任意のユーザーになりすます脆弱性 (CVE-2026-55040, CVSS 9.1) と、リモートコード実行 (RCE) を可能にする脆弱性 (CVE-2026-63520, CVSS 8.1) が組み合わされ、最終的に認証なしでのRCEが可能です。

■ 影響範囲
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Server 2016
※SharePoint Onlineは影響を受けません。

■ 対応手順
1. 自社で運用しているSharePoint Serverのバージョンを確認してください。
2. Microsoft公式のセキュリティ更新プログラムを適用し、最新の状態にアップデートしてください。

■ 参考情報
- Microsoft Security Update Guide

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Microsoft SharePoint Server Vulnerabilities (CVE-2026-55040 / CVE-2026-63520)

Dear IT/Security Team,

We are sharing information regarding a critical exploit chain discovered in Microsoft SharePoint Server.

■ Overview
An exploit chain involving CVE-2026-55040 (CVSS 9.1), which allows unauthenticated identity assumption, and CVE-2026-63520 (CVSS 8.1), an unsafe .NET type instantiation, enables unauthenticated Remote Code Execution (RCE) on the server.

■ Affected Products
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Server 2016
*SharePoint Online is NOT affected.

■ Mitigation Steps
1. Identify all on-premises SharePoint Server instances and their versions.
2. Apply the latest security updates provided by Microsoft immediately.

■ Reference
- Microsoft Security Update Guide

Priority: High
Deadline: Immediate
B
今週中

SAPは、CVSS 10.0の深刻な脆弱性を含む計28件のセキュリティノート

脆弱性🌐 英語ソース
🖥️ 製品SAP
🔢 CVECVE-2026-58231CVE-2026-44772CVE-2026-44758+1件
📅 2026-08-11📰 securityweek
📌 一言でいうと
SAPは、CVSS 10.0の深刻な脆弱性を含む計28件のセキュリティノートを公開しました。特にSAP Commerce Cloudの認証バイパス(CVE-2026-58231)や、Manufacturing Integration and Intelligenceにおけるコードインジェクション(CVE-2026-44772, CVE-2026-44758)などの重大な欠陥が修正されています。これらの脆弱性が悪用された場合、リモートから任意のコードが実行され、インフラ全体の完全な侵害に至る恐れがあります。
🔍該当判定
  • SAP Commerce Cloud(特にData Hub Adapter)を利用している
  • SAP Manufacturing Integration and Intelligence (MII) を利用している
  • 社内でSAP製の基幹システムやエンタープライズソフトウェアを運用している
上記いずれにも該当しない → 静観でOK
該当時の対応
SAPが提供する最新のセキュリティノートを確認し、該当する製品のパッチを速やかに適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】SAP製品の深刻な脆弱性 (CVE-2026-58231 他) 対応について

お疲れさまです。SAP製品における複数の深刻な脆弱性に関する情報共有です。

■ 概要
SAPより、CVSS 10.0を含む複数のクリティカルな脆弱性が報告されました。認証バイパスやコードインジェクションにより、リモートから任意のコマンド実行や内部コンポーネントへの不正アクセスが行われる可能性があります。

■ 影響範囲
- SAP Commerce Cloud (Data Hub Adapter)
- SAP Manufacturing Integration and Intelligence

■ 対応手順
1. SAP Security Patch Dayの最新ノートを確認し、自社環境のバージョンが対象か判定してください。
2. 該当する場合、速やかに修正パッチを適用してください。

■ 参考情報
- SAP Security Notes / GitHub Advisory

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Critical Vulnerabilities in SAP Products (CVE-2026-58231 et al.)

Dear IT/Security Team,

This is a notification regarding several critical vulnerabilities identified in SAP products.

■ Overview
SAP has released security notes for multiple critical flaws, including one with a CVSS score of 10.0. These vulnerabilities, including authentication bypass and code injection, could allow remote attackers to execute arbitrary commands and compromise the entire infrastructure.

■ Affected Scope
- SAP Commerce Cloud (Data Hub Adapter)
- SAP Manufacturing Integration and Intelligence

■ Action Plan
1. Review the latest SAP Security Notes to determine if your environment is affected.
2. Apply the necessary security patches immediately.

■ Reference
- SAP Security Notes / GitHub Advisory

Priority: High
Deadline: Immediate
B
今週中

OpenWrtのLuCIインターフェースにおいて、DHCPv6クライアントのホスト名(FQDN)を介した蓄積型クロスサイトスクリプティング(Stored…

脆弱性🌐 英語ソース
🔢 CVECVE-2026-61876
📅 2026-08-11📰 exploit_db
📌 一言でいうと
OpenWrtのLuCIインターフェースにおいて、DHCPv6クライアントのホスト名(FQDN)を介した蓄積型クロスサイトスクリプティング(Stored XSS)の脆弱性が発見されました。攻撃者はDHCPv6オプション39を使用して悪意のあるHTMLやJavaScriptを注入でき、これがLuCIのステータステーブルで不適切にレンダリングされます。影響を受けるバージョンはパッチ適用前のLuCI (luci-mod-status, luci-mod-network) です。
🔍該当判定
  • ルーターやネットワーク機器に「OpenWrt」というOSをインストールして利用している
  • OpenWrtの管理画面である「LuCI」を利用して設定変更や状態確認を行っている
  • IPv6環境で、DHCPv6による自動設定(ホスト名の通知など)を有効にしている
上記いずれにも該当しない → 静観でOK
該当時の対応
最新のパッチが適用されたOpenWrt/LuCIバージョンへのアップデートを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】OpenWrt LuCI CVE-2026-61876 対応について

お疲れさまです。OpenWrt LuCIの脆弱性に関する情報共有です。

■ 概要
DHCPv6クライアントのホスト名(FQDN)を介して悪意のあるスクリプトを注入できる蓄積型XSSの脆弱性が報告されました。CVSSスコアは8.8と高く、隣接ネットワーク上の攻撃者が管理画面にスクリプトを仕込むことが可能です。

■ 影響範囲
- 対象製品: OpenWrt LuCI (luci-mod-status, luci-mod-network)
- バージョン: パッチ適用前のバージョン(例: 25.12.0-rc1 等)

■ 対応手順
1. 利用中のOpenWrt/LuCIのバージョンを確認してください。
2. 脆弱性が修正された最新バージョンへアップデートを適用してください。

■ 参考情報
- Exploit-DB EDB-ID: 52637
- CVE-2026-61876

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] OpenWrt LuCI CVE-2026-61876

Dear IT Administration Team,

We are sharing information regarding a vulnerability in OpenWrt LuCI.

■ Overview
A stored cross-site scripting (XSS) vulnerability (CVE-2026-61876) has been identified. An unauthenticated attacker on an adjacent network can inject malicious HTML/JavaScript via DHCPv6 Client FQDN (option 39), which is then rendered unsafely in the LuCI status tables. The CVSS score is 8.8.

■ Affected Scope
- Product: OpenWrt LuCI (luci-mod-status, luci-mod-network)
- Version: Versions prior to the security patch (e.g., 25.12.0-rc1).

■ Mitigation Steps
1. Verify the current version of OpenWrt/LuCI in your environment.
2. Update to the latest patched version provided by the vendor.

■ Reference
- Exploit-DB EDB-ID: 52637
- CVE-2026-61876

Priority: High
Deadline: Immediate
B
今週中

AIコーディングアシスタントが利用するModel Context Protocol (MCP) の脆弱性を悪用した「GhostSplice」という攻撃手法

脆弱性🌐 英語ソース
📅 2026-08-11📰 hackernews
📌 一言でいうと
AIコーディングアシスタントが利用するModel Context Protocol (MCP) の脆弱性を悪用した「GhostSplice」という攻撃手法が報告されました。悪意のあるMCPサーバーが指示を断片化して送信することで、AIエージェントにSSHキーや環境変数などの機密情報を外部へ送信させることが可能です。単一の指示では拒否されるような攻撃的な要求も、複数のルーチンな指示に分割することで検知を回避し、エージェント側で再構成させる仕組みです。
🔍該当判定
  • CursorやClineなどのAIコーディングエディタを利用している
  • AIエディタに外部のMCPサーバー(Model Context Protocol)を連携させている
  • AIエディタにSSH鍵や環境変数(.env)などの機密情報へのアクセス権限を与えている
上記いずれにも該当しない → 静観でOK
該当時の対応
信頼できないMCPサーバーの導入を避け、AIエージェントに与える権限(ファイルアクセスやネットワーク通信)を最小限に制限することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Model Context Protocol (MCP) を利用したAIエージェントへの攻撃手法について

お疲れさまです。AIコーディングアシスタントにおける新たな攻撃手法「GhostSplice」に関する情報共有です。

■ 概要
悪意のあるMCPサーバーが、攻撃指示を複数の断片に分割してAIエージェントに送信し、機密情報(SSHキー、環境変数等)を窃取させる手法です。指示を分割することで、AIの安全フィルターによる検知を回避し、エージェント内部で指示を再構成させます。

■ 影響範囲
- Model Context Protocol (MCP) を利用して外部ツールと連携しているAIコーディングツールおよびエージェント

■ 対応手順
1. 開発環境で利用しているMCPサーバーの信頼性を確認し、未検証のサードパーティ製サーバーの利用を制限する。
2. AIエージェントがアクセス可能なディレクトリや環境変数の権限を最小化(Least Privilege)する。
3. エージェントによる外部へのデータ送信ログを監視し、不審な通信がないか確認する。

■ 参考情報
- ASSET Research Group による GhostSplice 調査レポート

対応優先度: 中
対応期限: 順次対応
Subject: [Security Advisory] AI Agent Exfiltration via Model Context Protocol (MCP)

Dear IT/Security Team,

We are sharing information regarding a new attack technique called "GhostSplice" targeting AI coding assistants.

■ Overview
GhostSplice allows a malicious MCP server to exfiltrate sensitive data (e.g., SSH keys, environment secrets) by splitting a malicious request into multiple routine-looking fragments. This bypasses safety filters by ensuring no single fragment is flagged as harmful, while the AI agent reconstructs the full instruction in its context.

■ Scope
- AI coding tools and agents utilizing the Model Context Protocol (MCP) for external tool integration.

■ Recommended Actions
1. Audit and restrict the use of unverified third-party MCP servers within development environments.
2. Implement the principle of least privilege for AI agents, limiting their access to sensitive files and environment variables.
3. Monitor outbound network traffic from AI agents for unauthorized data exfiltration.

■ Reference
- ASSET Research Group research on GhostSplice

Priority: Medium
Deadline: As soon as possible
C
月内に

Red Hat Advanced Cluster Management for Kubernetes 2 において、権限昇格の脆弱性 (CVE-2026-100…

脆弱性🌐 英語ソース
🖥️ 製品Red Hat
🔢 CVECVE-2026-10090
📅 2026-08-11📰 cccs
📌 一言でいうと
Red Hat Advanced Cluster Management for Kubernetes 2 において、権限昇格の脆弱性 (CVE-2026-10090) が報告されました。この脆弱性により、namespace edit 権限を持つユーザーがクラスター範囲の ClusterRoleBinding を展開し、cluster-admin 権限を取得できる可能性があります。影響を受けるユーザーは、速やかに最新のセキュリティアップデートを適用することが推奨されます。
🔍該当判定
  • Red Hat Advanced Cluster Management for Kubernetes 2 を利用している
  • Kubernetes環境でマルチクラスター管理(複数のクラスターの一元管理)を行っている
  • 特定のユーザーに namespace edit 権限を付与して運用している
上記いずれにも該当しない → 静観でOK
該当時の対応
Red Hat カスタマーポータルを確認し、CVE-2026-10090 に対応する最新のセキュリティアップデートを適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Red Hat Advanced Cluster Management for Kubernetes 2 (CVE-2026-10090) 対応について

お疲れさまです。Red Hat 製品の脆弱性に関する情報共有です。

■ 概要
Red Hat Advanced Cluster Management for Kubernetes 2 において、権限昇格の脆弱性 (CVE-2026-10090) が発見されました。namespace edit 権限を持つユーザーが、不適切に ClusterRoleBinding を作成することで、最高権限である cluster-admin を取得できる可能性があります。

■ 影響範囲
- Red Hat Advanced Cluster Management for Kubernetes 2

■ 対応手順
1. Red Hat カスタマーポータルにて、自社環境のバージョンが影響を受けるか確認してください。
2. 提供されている最新のセキュリティアップデートを適用してください。

■ 参考情報
- Red Hat Customer Portal (CVE-2026-10090)

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Red Hat Advanced Cluster Management for Kubernetes 2 (CVE-2026-10090)

Dear IT Administration Team,

We are sharing information regarding a vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2.

■ Overview
A privilege escalation vulnerability (CVE-2026-10090) has been reported. An attacker with 'namespace edit' permissions can deploy a cluster-scoped ClusterRoleBinding to escalate their privileges to 'cluster-admin'.

■ Scope
- Red Hat Advanced Cluster Management for Kubernetes 2

■ Mitigation Steps
1. Verify the current version of your environment via the Red Hat Customer Portal.
2. Apply the latest security updates to remediate the vulnerability.

■ Reference
- Red Hat Customer Portal (CVE-2026-10090)

Priority: High
Deadline: Immediate
C
月内に

Mozillaは、FirefoxおよびThunderbirdの一部のアーティファクトに使用されるGPG署名サブキーがGitHubのリポジトリで誤って公開されたた…

脆弱性🌐 英語ソース📰 2記事🌐 1 country
🇺🇸 US (2)
🖥️ 製品Firefox
📅 2026-08-11📰 securityweek
📌 一言でいうと
Mozillaは、FirefoxおよびThunderbirdの一部のアーティファクトに使用されるGPG署名サブキーがGitHubのリポジトリで誤って公開されたため、新しいキーを発行したと発表しました。公開されたキーは限定的な権限を持つプライベートリポジトリに保存されており、不正アクセスがあった証拠は見つかっていません。しかし、万が一攻撃者がこのキーを入手した場合、悪意のあるファイルを正当な署名付きで配布するサプライチェーン攻撃のリスクがありました。
🔍該当判定
  • Linux OS上で、FirefoxやThunderbirdを公式サイト以外のミラーサイトや外部リポジトリからインストールして利用している
  • FirefoxやThunderbirdのインストール時に、GPG鍵(署名)を用いてファイルの正当性を手動で検証する運用を行っている
  • Linux向けパッケージ(RPM形式やtarball形式)のFirefox/Thunderbirdを社内サーバーで配布・管理している
上記いずれにも該当しない(Windows/Mac版を通常通り利用している等) → 静観でOK
該当時の対応
Mozillaの公式発表を確認し、最新の署名キーが適用された正規の配布チャネルからソフトウェアをアップデートすること。不審なソースからのパッケージインストールを避けること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Mozilla Firefox/Thunderbird GPG署名キー更新について

お疲れさまです。Mozillaによる署名キーの更新に関する情報共有です。

■ 概要
MozillaのGPG署名サブキーがGitHubのプライベートリポジトリで誤って公開されたため、新しいキーが発行されました。監査の結果、外部への流出や悪用は確認されていませんが、潜在的なサプライチェーン攻撃のリスク(悪意のあるファイルの正当な署名)があったため、予防的な措置が取られました。

■ 影響範囲
- FirefoxおよびThunderbirdのLinux向けアーティファクト(tarballs, RPM packages, checksum files)

■ 対応手順
1. 組織内でLinux版Firefox/Thunderbirdを配布・管理している場合、最新の公式署名キーが適用されているか確認してください。
2. 正規のMozillaリポジトリ以外からのパッケージ取得を禁止するポリシーを再徹底してください。

■ 参考情報
- Mozilla公式発表

対応優先度: 低
対応期限: 確認次第
Subject: [Info] Update on Mozilla Firefox/Thunderbird GPG Signing Keys

Dear team,

This is to inform you that Mozilla has issued a new GPG signing subkey for certain Firefox and Thunderbird artifacts due to the accidental exposure of a previous key in a private GitHub repository.

■ Overview
Although audit records show no evidence of unauthorized access, the exposure created a theoretical risk of a supply chain attack where an attacker could sign malicious files as authentic. Mozilla has proactively rotated the keys to mitigate this risk.

■ Scope
- Firefox and Thunderbird artifacts for Linux (tarballs, RPM packages, and checksum files).

■ Action Items
1. If you manage the deployment of Linux-based Firefox or Thunderbird installations, ensure that you are using the latest official signing keys.
2. Reinforce policies to ensure software is only downloaded from official, trusted Mozilla channels.

■ Reference
- Mozilla Official Announcement

Priority: Low
Deadline: Upon review
C
月内に

SAPは2026年8月の月次セキュリティアップデート(AV26-798)

脆弱性🌐 英語ソース📰 2記事🌐 2 countries
🇨🇦 Canada · 🇮🇹 Italy
🖥️ 製品SAP
📅 2026-08-11📰 cccs
📌 一言でいうと
SAPは2026年8月の月次セキュリティアップデート(AV26-798)を公開しました。このアドバイザリでは、SAP Commerce Cloud、SAP Manufacturing Integration and Intelligence、SAP NetWeaverABAP Platformなどの複数の製品における脆弱性が報告されています。影響を受けるバージョンは多岐にわたるため、管理者は速やかにパッチ適用を確認することが推奨されます。
🔍該当判定
  • SAP Commerce Cloud(特にバージョン2211)を利用している
  • SAP NetWeaver または ABAP Platform を利用している
  • SAP Manufacturing Integration and Intelligence (MII) を利用している
  • SAP BusinessObjects Business Intelligence Platform を利用している
上記いずれにも該当しない → 静観でOK
該当時の対応
SAP公式のセキュリティノートを確認し、利用している製品のバージョンが対象であるかを確認の上、最新のセキュリティパッチを適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】SAP 2026年8月セキュリティアップデート (AV26-798) 対応について

お疲れさまです。SAP製品の脆弱性に関する情報共有です。

■ 概要
SAPより2026年8月の月次セキュリティ rollup (AV26-798) が公開されました。複数の製品において脆弱性が修正されています。

■ 影響範囲
- SAP Commerce Cloud (Data Hub Adapter)
- SAP Manufacturing Integration and Intelligence (MII)
- SAP NetWeaver / ABAP Platform
- SAP Change and Transport System Attach Tool (ctsattach)
- SAP ABAP Developer Tools
- SAP BusinessObjects Business Intelligence Platform
※詳細なバージョンは公式アドバイザリをご確認ください。

■ 対応手順
1. 自社で利用しているSAP製品およびバージョンのリストアップ
2. SAP Security Notesを確認し、該当するパッチの有無を特定
3. メンテナンスウィンドウを確保し、最新のセキュリティアップデートを適用

■ 参考情報
- SAP Security Advisory AV26-798

対応優先度: 高
対応期限: 次回メンテナンスサイクルまで
Subject: [Security] SAP August 2026 Security Updates (AV26-798)

Dear IT Administration Team,

SAP has released the August 2026 monthly security rollup (AV26-798) to address vulnerabilities in several core products.

■ Overview
This update provides critical security fixes for multiple SAP components to prevent potential exploitation.

■ Affected Scope
- SAP Commerce Cloud (Data Hub Adapter)
- SAP Manufacturing Integration and Intelligence (MII)
- SAP NetWeaver / ABAP Platform
- SAP Change and Transport System Attach Tool (ctsattach)
- SAP ABAP Developer Tools
- SAP BusinessObjects Business Intelligence Platform

■ Action Plan
1. Identify the current versions of SAP products deployed in the environment.
2. Cross-reference with the SAP Security Notes for AV26-798.
3. Schedule and apply the necessary security patches.

■ Reference
- SAP Security Advisory AV26-798

Priority: High
Deadline: Next scheduled maintenance window
C
月内に

WordPressプラグインベンダーであるBdThemesのサプライチェーン攻撃

脆弱性🌐 英語ソース
🖥️ 製品WordPress
📅 2026-08-11📰 hackernews
📌 一言でいうと
WordPressプラグインベンダーであるBdThemesのサプライチェーン攻撃が判明しました。攻撃者は公式リポジトリのソースコードではなく、管理画面のプロモーションバナーが取得する外部JSONデータを汚染し、不正な管理者アカウントを作成させる手法を用いています。影響を受けるプラグインにはElement Pack Addons for Elementorなどが含まれており、WordPressチームは一時的にダウンロードを停止しています。
🔍該当判定
  • WordPressで『Element Pack Addons for Elementor』を利用している
  • WordPressで『Live Copy Paste for Elementor』を利用している
  • WordPressで『Pixel Gallery Addons for Elementor』を利用している
  • WordPressで『Prime Slider Addons for Elementor』を利用している
上記いずれにも該当しない → 静観でOK
該当時の対応
影響を受けるプラグイン(Element Pack Addons for Elementor等)をインストールしている場合は、速やかに管理画面のユーザーリストを確認し、身に覚えのない管理者アカウントが作成されていないかチェックしてください。また、ベンダーからの修正版リリースを待ち、最新バージョンへ更新してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】BdThemes製WordPressプラグインのサプライチェーン攻撃への対応について

お疲れさまです。BdThemes製プラグインにおけるサプライチェーン攻撃に関する情報共有です。

■ 概要
攻撃者がプラグインの管理画面に表示されるプロモーションバナーが参照する外部JSONデータを汚染し、サイトに不正な管理者アカウントを自動作成させる攻撃が確認されました。ソースコード自体の改ざんではなく、外部データストリームを悪用した巧妙な手法です。

■ 影響範囲
- Element Pack Addons for Elementor [bdthemes-element-pack-lite]
- Live Copy Paste for Elementor [live-copy-paste]
- Pixel Gallery Addons for Elementor [pixel-gallery]
- Prime Slider Addons for Elementor

■ 対応手順
1. 自社管理サイトで上記プラグインが利用されているか確認する。
2. 利用している場合、WordPress管理画面の「ユーザー」一覧を確認し、心当たりのない管理者権限アカウントが存在しないか調査する。
3. 不正アカウントを発見した場合は直ちに削除し、パスワードの変更およびセキュリティ監査を実施する。
4. WordPress公式リポジトリでのダウンロード再開および修正版のリリースを確認し、速やかに更新を適用する。

■ 参考情報
- Wordfence / WordPress.org プラグインチーム通知

対応優先度: 高
対応期限: 至急
Subject: [Security Alert] Supply Chain Attack on BdThemes WordPress Plugins

Dear IT/Security Team,

We are sharing information regarding a supply chain compromise affecting plugins from the vendor BdThemes.

■ Overview
Threat actors have poisoned a static remote JSON data stream fetched by administrative promotional banners in several BdThemes plugins. This allows the attackers to create rogue administrator accounts on affected WordPress sites without modifying the source code within the official WordPress.org repository.

■ Affected Products
- Element Pack Addons for Elementor [bdthemes-element-pack-lite]
- Live Copy Paste for Elementor [live-copy-paste]
- Pixel Gallery Addons for Elementor [pixel-gallery]
- Prime Slider Addons for Elementor

■ Action Plan
1. Identify if any of the aforementioned plugins are installed on company-managed WordPress sites.
2. Review the user list in the WordPress admin dashboard for any unauthorized administrator accounts.
3. If rogue accounts are found, delete them immediately and perform a full security audit of the site.
4. Monitor for official updates and apply patches as soon as they are available from the vendor/WordPress repository.

■ Reference
- Wordfence / WordPress.org Plugins Team

Priority: High
Deadline: Immediate