2026年7月10日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Balbooa Forms が CISA KEV に新規掲載 — 実環境での悪用を確認。
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

実際の悪用を確認

CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type

  • 実環境での悪用(CISA KEV)
  • CISA KEV に掲載
  • リモートコード実行の露出リスク

Balbooa Forms RCE は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。

重大な露出リスク

CVE-2026-10768 Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.

  • CVSS 9.8
  • 管理者/root への権限昇格の可能性

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2026-12761 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPres...

  • CVSS 9.8
  • インターネット公開 CMS への影響

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

Balbooa Forms Unrestricted Upload of File with Dangerous Type

iCagenda Unrestricted Upload of File with Dangerous Type

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2026-10768 CVSS 9.8

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.

CVE-2026-11913 CVSS 9.8

vulnerability in Drupal Mother May I allows .

CVE-2026-12535 CVSS 9.8

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Inje...

CVE-2026-12761 CVSS 9.8

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass...

CVE-2026-15089 CVSS 9.1

vulnerability in Drupal Commerce guest registration allows .

CVE-2026-20744 CVSS 9.3

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

CVE-2026-55879 CVSS 9.3

OpenReplay is a self-hosted session replay suite.

CVE-2026-55884 CVSS 9.2

Tilt defines dev environments as code for microservice apps on Kubernetes.

CVE-2026-57807 CVSS 9.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd.

CVE-2026-9726 CVSS 9.8

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket...

Critical 公開を見る

cvelogic Threat Intelligence