実際の悪用を確認
CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type
- 実環境での悪用(CISA KEV)
- CISA KEV に掲載
- リモートコード実行の露出リスク
Balbooa Forms RCE は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。
日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。
最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。
実際の悪用を確認
Balbooa Forms RCE は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。
重大な露出リスク
新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。
重大な露出リスク
新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。
CISA KEV — 実環境での悪用が確認
Balbooa Forms Unrestricted Upload of File with Dangerous Type
iCagenda Unrestricted Upload of File with Dangerous Type
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.
vulnerability in Drupal Mother May I allows .
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Inje...
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass...
vulnerability in Drupal Commerce guest registration allows .
The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.
OpenReplay is a self-hosted session replay suite.
Tilt defines dev environments as code for microservice apps on Kubernetes.
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd.
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket...