B
今週中
米国CISAは、GitLab、JFrog Artifactory、およびConnectWise ScreenConnectの脆弱性を「既知の悪用された脆弱性(K…
📌 一言でいうと
米国CISAは、GitLab、JFrog Artifactory、およびConnectWise ScreenConnectの脆弱性を「既知の悪用された脆弱性(KEV)」カタログに追加しました。追加された脆弱性には、CVSSスコアが10.0に達するGitLabのパストラバーサル脆弱性や、ConnectWiseの権限管理不備などが含まれています。これらの脆弱性は実際に攻撃に利用されているため、迅速なパッチ適用が強く推奨されています。
🔍該当判定
- GitLab (Community Edition または Enterprise Edition) を自社サーバーで運用している
- JFrog Artifactory を利用している
- ConnectWise ScreenConnect をリモート操作ツールとして利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受ける製品の最新バージョンへのアップデートを直ちに実施し、CISA KEVカタログおよびベンダーのアドバイザリを確認してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】GitLab, JFrog, ConnectWise 脆弱性の CISA KEV 追加について
お疲れさまです。CISA KEVカタログへの脆弱性追加に関する情報共有です。
■ 概要
CISAが、実際に悪用が確認された以下の脆弱性をKEVカタログに追加しました。特にGitLabの脆弱性はCVSS 10.0と極めて危険な状態です。
- CVE-2026-85706 (GitLab): Path Traversal (CVSS 10.0)
- CVE-2026-84869 (ConnectWise ScreenConnect): Improper Privilege Management (CVSS 9.9)
- CVE-2026-42016 (JFrog Artifactory): Incorrect Authorization (CVSS 8.1)
- CVE-2026-42018 (JFrog Artifactory): Improper Authentication (CVSS 7.5)
■ 影響範囲
- GitLab Community Edition / Enterprise Edition
- JFrog Artifactory
- ConnectWise ScreenConnect
■ 対応手順
1. 自社環境で上記製品の利用有無およびバージョンを確認してください。
2. 各ベンダーが提供している最新のセキュリティパッチを適用してください。
■ 参考情報
- CISA Known Exploited Vulnerabilities (KEV) Catalog
対応優先度: 高
対応期限: 至急
お疲れさまです。CISA KEVカタログへの脆弱性追加に関する情報共有です。
■ 概要
CISAが、実際に悪用が確認された以下の脆弱性をKEVカタログに追加しました。特にGitLabの脆弱性はCVSS 10.0と極めて危険な状態です。
- CVE-2026-85706 (GitLab): Path Traversal (CVSS 10.0)
- CVE-2026-84869 (ConnectWise ScreenConnect): Improper Privilege Management (CVSS 9.9)
- CVE-2026-42016 (JFrog Artifactory): Incorrect Authorization (CVSS 8.1)
- CVE-2026-42018 (JFrog Artifactory): Improper Authentication (CVSS 7.5)
■ 影響範囲
- GitLab Community Edition / Enterprise Edition
- JFrog Artifactory
- ConnectWise ScreenConnect
■ 対応手順
1. 自社環境で上記製品の利用有無およびバージョンを確認してください。
2. 各ベンダーが提供している最新のセキュリティパッチを適用してください。
■ 参考情報
- CISA Known Exploited Vulnerabilities (KEV) Catalog
対応優先度: 高
対応期限: 至急
Subject: [Alert] CISA KEV Addition: GitLab, JFrog, and ConnectWise Vulnerabilities
Dear Team,
CISA has added the following vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild:
- CVE-2026-85706 (GitLab): Path Traversal (CVSS 10.0)
- CVE-2026-84869 (ConnectWise ScreenConnect): Improper Privilege Management (CVSS 9.9)
- CVE-2026-42016 (JFrog Artifactory): Incorrect Authorization (CVSS 8.1)
- CVE-2026-42018 (JFrog Artifactory): Improper Authentication (CVSS 7.5)
Scope:
- GitLab Community and Enterprise Editions
- JFrog Artifactory
- ConnectWise ScreenConnect
Required Actions:
1. Identify if these products are deployed within our environment.
2. Apply the latest security updates provided by the respective vendors immediately.
Reference:
- CISA KEV Catalog
Priority: High
Deadline: Immediate
Dear Team,
CISA has added the following vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild:
- CVE-2026-85706 (GitLab): Path Traversal (CVSS 10.0)
- CVE-2026-84869 (ConnectWise ScreenConnect): Improper Privilege Management (CVSS 9.9)
- CVE-2026-42016 (JFrog Artifactory): Incorrect Authorization (CVSS 8.1)
- CVE-2026-42018 (JFrog Artifactory): Improper Authentication (CVSS 7.5)
Scope:
- GitLab Community and Enterprise Editions
- JFrog Artifactory
- ConnectWise ScreenConnect
Required Actions:
1. Identify if these products are deployed within our environment.
2. Apply the latest security updates provided by the respective vendors immediately.
Reference:
- CISA KEV Catalog
Priority: High
Deadline: Immediate