2026年4月1日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Google Dawn が CISA KEV に新規掲載 — 実環境での悪用を確認。
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

実際の悪用を確認

CVE-2026-5281 Google Dawn Use-After-Free

  • 実環境での悪用(CISA KEV)
  • CISA KEV に掲載

Google Dawn Use-After-Free は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。

重大な露出リスク

CVE-2026-34569 Ci4-cms-erp Ci4ms privilege escalation

  • CVSS 9.9
  • 管理者/root への権限昇格の可能性

新たな重大 Ci4-cms-erp Ci4ms privilege escalation(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2026-34571 Ci4-cms-erp Ci4ms XSS

  • CVSS 9.9

新たな重大 Ci4-cms-erp Ci4ms XSS(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2026-34559 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34560 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34563 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34564 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34565 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34566 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34567 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34568 CVSS 9.1

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34569 CVSS 9.9

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

CVE-2026-34571 CVSS 9.9

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme supp...

Critical 公開を見る

cvelogic Threat Intelligence