2026年3月4日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2025-70222 Dlink Dir-513 Firmware Buffer Overflow

  • CVSS 9.8

新たな重大 Dlink Dir-513 Firmware Buffer Overflow(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2025-40926 Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely.

  • CVSS 9.8

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2026-3257 UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library.

  • CVSS 9.8

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2024-57854 CVSS 9.1

Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator.

CVE-2025-40926 CVSS 9.8

Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely.

CVE-2025-40931 CVSS 9.1

Apache::Session::Generate::MD5 versions through 1.94 for Perl create insecure session id.

CVE-2025-70222 CVSS 9.8

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formLogin,goform/getAuthCode.

CVE-2026-2833 CVSS 9.3

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades.

CVE-2026-2835 CVSS 9.3

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests.

CVE-2026-29000 CVSS 9.3

pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing en...

CVE-2026-29127 CVSS 9.2

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory.

CVE-2026-3257 CVSS 9.8

UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library.

CVE-2026-3381 CVSS 9.8

Compress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib.

Critical 公開を見る

cvelogic Threat Intelligence