2026年4月7日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2026-27143 Arithmetic over induction variables in loops were not correctly checked for underflow or overflow.

  • CVSS 9.8

新たな重大 Golang Go Memory Corruption(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2026-31789 Openssl Code Execution

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Openssl Code Execution(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2026-3296 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...

  • CVSS 9.8
  • インターネット公開 CMS への影響

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2026-1346 CVSS 9.3

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Id...

CVE-2026-27143 CVSS 9.8

Arithmetic over induction variables in loops were not correctly checked for underflow or overflow.

CVE-2026-31789 CVSS 9.8

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platf...

CVE-2026-3296 CVSS 9.8

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserializat...

CVE-2026-33439 CVSS 9.3

Open Access Management (OpenAM) is an access management solution.

CVE-2026-34078 CVSS 9.3

Flatpak is a Linux application sandboxing and distribution framework.

CVE-2026-39397 CVSS 9.4

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder.

SiYuan is a personal knowledge management system.

CVE-2026-39847 CVSS 9.1

Emmett is a full-stack Python web framework designed with simplicity.

Critical 公開を見る

cvelogic Threat Intelligence