昨日からの変化
- NEW — Zimbra:MicrosoftがCVE-2026-73570の悪用を公開。JSP web shell、reverse shell、権限昇格、persistenceまで確認した。
- NEW — Cisco SD-WAN:Cisco PSIRTがCVE-2026-76504のactive exploitationを確認した。
- UPDATED — NetScaler:Unit 42がCVE-2026-88771/CVE-2026-88772の公開前後の活動とローテーションするインフラを追加した。
- NEW — FUJIFILM/Sharp MFP:JVNがWeb管理画面のpath traversal CVE-2026-78249を公開した。
優先対応
- 直ちに: 公開Zimbraを修正し、JSP web shell、reverse shell、権限昇格、persistenceを調査する。
-
直ちに: Cisco Catalyst SD-WAN Managerはupgrade前にadmin-techを取得し、修正版へ更新後、
vmanage-server.logを確認する。 - 直ちに: 修正前に公開されていたNetScalerで侵害調査を続け、新しいinfrastructureをretrospective huntへ追加する。
- 本日:対象FUJIFILM/Sharp複合機のfirmwareを更新し、管理画面を信頼できないnetworkから隔離する。
重点脅威
Zimbra CVE-2026-73570が公開mail serverで悪用
- Severity
- Critical
- Status
- Confirmed active exploitation
- CVE
- CVE-2026-73570
- Affected
- 影響を受けるSNMP/notification経路を持つZimbra Collaboration
Microsoftは未認証command injectionからJSP web shell、reverse shell、権限昇格、persistenceへ進む攻撃を確認した。活動期間に公開されていた環境は、patch後も侵害確認が必要になる。
Zimbraの修正を適用し、web root、process tree、scheduled task/service、外向き通信を確認する。cleanup前にforensic dataを保存する。
Sources (1)
Cisco Catalyst SD-WAN Manager CVE-2026-76504が悪用
- Severity
- Critical
- Status
- Confirmed active exploitation / zero-day disclosure
- CVSS
- 9.8
- CVE
- CVE-2026-76504
- Affected
- Cisco advisory記載のCatalyst SD-WAN Manager
URI encodingの処理不備でAPI認証ruleをbypassし、未認証remote attackerがadmin-user権限でAPIへアクセスできる。Cisco PSIRTは9月のactive exploitationを確認している。
upgrade前にadmin-techを収集し、修正版へ更新する。Cisco TACへbundleを渡してIOC scanを依頼できるほか、vmanage-server.logの異常なj_security_checkを確認する。
NetScaler調査に新しいインフラとpersistence情報
- Severity
- Critical
- Status
- Confirmed active exploitation / ongoing follow-up
- CVE
- CVE-2026-88771, CVE-2026-88772
- Affected
- exploit window中に公開されていたNetScaler ADC / Gateway
Unit 42は公開前後の攻撃、ローテーションするインフラ、persistenceを追加した。9月27–28日のeventへのmaterial updateであり、新しい脆弱性ではない。
新しいIPはretrospective huntに使えるが、time contextとasset contextを合わせる。hosting IPは再割当があるため永久blocklistには向かない。
IOC (7)
66.135.19[.]18167.99.111[.]203142.93.85[.]227104.248.74[.]206137.184.91[.]207162.33.178[.]9193.149.176[.]207
Sources (1)
重要な脆弱性
FUJIFILM/Sharp複合機 CVE-2026-78249
- Severity
- Medium
- Status
- JVNで悪用確認なし
- CVE
- CVE-2026-78249
- Affected
- JVN記載の機種・firmware
Web管理インターフェースにpath traversalがある。修正版firmwareを適用し、管理面を信頼できないnetworkへ公開しない。
Sources (1)
IOCサマリー
| 種別 | Indicator | Context |
|---|---|---|
| IPv4 | 66.135.19[.]18 |
NetScaler exploitation infrastructure |
| IPv4 | 167.99.111[.]203 |
NetScaler exploitation infrastructure |
| IPv4 | 142.93.85[.]227 |
NetScaler exploitation infrastructure |
| IPv4 | 104.248.74[.]206 |
NetScaler exploitation infrastructure |
| IPv4 | 137.184.91[.]207 |
NetScaler exploitation infrastructure |
| IPv4 | 162.33.178[.]9 |
NetScaler exploitation infrastructure |
| IPv4 | 193.149.176[.]207 |
NetScaler exploitation infrastructure |
本日の所見
- ZimbraとCiscoはexploit確認済みのため、patch後も侵害調査が必要になる。
- NetScalerはCVEが同じでも、攻撃infrastructureとpost-exploitation情報が更新された。こうした変化はdaily reportでUPDATEとして残す価値がある。
0 件のコメント