2026年1月28日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2025-57792 Explorance Blue SQL Injection

  • CVSS 10

新たな重大 Explorance Blue SQL Injection(CVSS 10)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2026-24897 Erugo is a self-hosted file-sharing platform.

  • CVSS 10
  • 管理者/root への権限昇格の可能性

新たな重大 Erugo privilege escalation(CVSS 10)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2025-57795 Explorance Blue RCE

  • CVSS 9.9
  • リモートコード実行の露出リスク

新たな重大 Explorance Blue RCE(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2025-40553 CVSS 9.8

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code ex...

CVE-2025-40554 CVSS 9.8

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacke...

CVE-2025-57792 CVSS 10

Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web a...

CVE-2025-57794 CVSS 9.1

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface.

CVE-2025-57795 CVSS 9.9

Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component.

CVE-2025-61140 CVSS 9.8

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

CVE-2025-69602 CVSS 9.1

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identif...

CVE-2026-1056 CVSS 9.8

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'gene...

CVE-2026-24685 CVSS 9.4

OpenProject is an open-source, web-based project management software.

CVE-2026-24897 CVSS 10

Erugo is a self-hosted file-sharing platform.

Critical 公開を見る

cvelogic Threat Intelligence