PunchKano begins diphtheria immunisation in five Kano LGsRTP DesportoFrancisco Cabral na final de pares em HangzhouESPN DeportesGrecia derrotó a Alemania por primera vez en la historia y golpeó a Klopp en su debut ante su públicoThe Jerusalem PostIsrair awaits final approval for Tokyo, Miami flights, adds new European destinations for 2027Daily MaverickWe worried AI would make things up, we should also worry when it doesn’tInquirerRains to continue in Visayas, Mindanao due to ITCZ until Sept. 30Bollywood HungamaVinod Kapri's Pyre to release in theaters on October 23, 2026BlickNächstes Amt abgelegt: Jens Spahn zieht sich aus Haushaltsausschuss zurückRapplerPhilippines should fix tax gaps and procurement, not raise tax rates – WBSportstarIndia in Athletics LIVE Updates, Asian Games 2026: Vithya Ramraj breaks National Record to win 400m hurdles bronze; Javelin throw final at 4:45 PM ISTIl Fatto QuotidianoMorto Stefano Milani, il tifoso del Milan diventato famoso su X. Da Bertolucci a Valenti: “Ha lottato come nessuno, mai un passo indietro”7sur7“Pourquoi je perds toujours?”: quand André Agassi taquine Alexander Zverev
The Daily Newsstand · Free, Always
Monday, September 28, 2026

[ITmedia News] SharePointのコード生成不備を突く脆弱性、実際の攻撃で悪用 米CISAが警告

Translate

著者 梅林日奈子 梅林日奈子

[ITmedia]

 米サイバーセキュリティ・インフラセキュリティ庁(CISA)は9月25日(現地時間)、米Microsoftの「SharePoint Server」の脆弱性が実際のサイバー攻撃で悪用されているとして、「既知の悪用脆弱性(KEV)」リストに追加した。悪用されると、攻撃者がサーバー上で不正なプログラムを動かす恐れがある。

CISAによる公表

 対象は「CVE-2026-65660」という脆弱性。Microsoftによると、プログラムのコードを生成する仕組みに不備があり、SharePointにログインできる攻撃者が細工したリクエストを送ることで、サーバー上で不正な処理を実行できるという。

 また、カナダのサイバーセキュリティ当局によると、ログインせずに利用できる「匿名アクセス」を許可したサーバーでは、他のSharePointの脆弱性と組み合わせることで、認証なしに不正なプログラムを実行できるという。同局は、過去のセキュリティアップデートを十分に適用していない環境では、特に侵害のリスクが高いとしている。

 影響を受けるのは、「SharePoint Enterprise Server 2016」「SharePoint Server 2019」「SharePoint Server Subscription Edition」のうち、この脆弱性の修正が適用されていないバージョン。Microsoftは8月11日付で同脆弱性の情報を公開しており、各製品に該当する更新プログラムを全て適用するよう求めている。

 CISAは、こうした脆弱性がサイバー攻撃の侵入口として頻繁に悪用され、米連邦政府のシステムに重大なリスクをもたらすと警告。政府機関に限らず、企業を含む全ての組織に対し、KEVリストに掲載された脆弱性への対策を優先するよう呼び掛けている。

View the original on ITmedia →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.