Topic Collection / Japan Vulnerability Records
Japan Vulnerability Signals
Official JVN iPedia records, guarded JPCERT/CC alert records, guarded IPA icat security-alert records, and NISC/NCO national-warning notices, normalized into an English-first monitoring layer for Japanese supplier, product, CVE, CERT advisory, and national cyber-warning review. Records enter the database before any article decision.
Server-Rendered Database Proof
Japan records are counted before browser hydration.
This collection renders database totals, source-family counts, freshness, and export links from the public summary first. The browser then loads a capped record list for interactive search.
Summary generated 2026-07-12 05:18. If the record list is still loading, these server-side counts remain the collection baseline.
Source Status
Core Japan vulnerability, CERT, and NISC layer
Japan JVN latest polling/backfill, scheduled JPCERT/CC alert polling/backfill, guarded scheduled IPA icat latest polling, and guarded NISC/NCO public-warning records are active. Monthly vendor patch-cycle and broad policy/reference rows remain review-only.
The database has active monitoring records for this collection. A quiet period means the source did not publish matching records, not that the page is broken.
What this collection covers
JVN iPedia records identify affected products, CVEs, weakness types, vendors, reporting organizations, and remediation context. JPCERT/CC alerts, IPA icat security-alert rows, and NISC/NCO public warnings add official Japan CERT/government prioritization for selected security alerts, campaign warnings, ransomware/DDoS guidance, and national cyber-warning context. Nogosee stores them as monitoring records so teams can search Japan exposure without turning every source note into a thin article.
Collection status
The latest JVN feed is active, official yearly JVN backfill is running in small newest-to-oldest segments, JPCERT/CC alert coverage is scheduled, IPA icat latest polling is guarded by D1 overlap checks, and NISC/NCO warning-list rows are guarded/manual with explicit allowlists. Japan remains focused on vulnerability, CERT, and national-warning depth before broader Japan procurement expansion.
Enterprise Handoff
Turn this public slice into a monitored workflow
Start with capped public records for Japan Vulnerability Signals, then request the minimum private access needed for repeat review, team routing, or historical analysis.
Evaluate The Slice
Open the tracker preset and capped CSV first, then request a bounded evaluation export only if the public view fits your review queue.
Open tracker presetDownload capped CSVRequest evaluation exportAutomate Monitoring
Use the public RSS feed for lightweight follow-up, or request recurring feed/API access for SIEM, vendor-risk, and internal dashboard workflows.
Open RSS feedRequest recurring feedRequest API integrationScope Team Access
Ask for historical export or custom monitoring when a team needs country, sector, source-family, entity, or threat-theme coverage beyond public caps.
Request historical exportRequest team monitoring setupPublic pages prove workflow fit without exposing private source baskets, full historical archives, scoring weights, matching logic, prompts, or anti-abuse controls.
Use this as a supplier exposure workflow
Search by CVE, product, vendor, weakness, CERT advisory, or sector. Open the official source for verification, then use the tracker preset or capped CSV sample for weekly review. Full data-feed access stays request-only.
529 rendered records. Public exports are capped; commercial feeds are available by request.
Highest-priority Japan signals
Reflected cross-site scripting vulnerability in multiple laser printers and MFPs which implement Ricoh Web Image Monitor
Web Image Monitor provided by Ricoh Company, Ltd. is a web server that is included in and runs on laser printers and MFPs (multifunction printers). Web Image Monitor contains the vulnerability listed below. Reflected cross-site scripting (CWE-79) - CVE-2026-56809 Tomasz Holeksa of Pentest Limited reported this vulnerability to Ricoh Company, Ltd. directly and coordinated. After the coordination, Ricoh Company, Ltd...
Published 2026-07-10 / Japan JVN iPedia / JVN iPedia / enterprise-softwareMultiple vulnerabilities in the installer for Pupsman
The installer for Pupsman provided by Fuji Electric Co.,Ltd. contains multiple vulnerabilities listed below: Uncontrolled search path element (CWE-427) - CVE-2026-56437 The CVSS vectors above assume that a victim user is directed to place a specially crafted DLL file in the same folder as the affected installer and to execute the installer. Incorrect default permissions (CWE-276) - CVE-2026-57895 Kazuma Matsumoto ...
Published 2026-07-08 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceSEIKO EPSON printers and scanners Web Config vulnerable to cross-site request forgery
Web Config embedded in multiple printers and scanners provided by SEIKO EPSON CORPORATION contains the following vulnerability. Cross-site request forgery (CWE-352) - CVE-2026-58315 Kentaro Ishii of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-07-07 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceSeiko Solutions SkyBridge MB-A100/MB-A110 vulnerable to OS command injection
SkyBridge MB-A100/MB-A110 provided by Seiko Solutions Inc. contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-50043 Takeshi Kuramori and Kaori Takashima of National Institute of Information and Communications Technology, Cybersecurity Research Institute reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-07-01 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceRPG MAKER MV and MZ vulnerable to OS command injection
RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. are game development tools, which provide "save data" facility to create a file to preserve game status and related parameters. A user can save the current game status to a save-file, and later load the file to resume playing the game. When loading a save-file, RPG MAKER MV and MZ fail to properly treat crafted contents, and may lead to OS command injection....
Published 2026-06-30 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceDGM3103SCT vulnerable to OS command injection
DGM3103SCT provided by AVTECH Security Corporation contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-56808 Tomoya KITAGAWA, Satoki TSUJI, Seiya NAKATA, and Yudai FUJIWARA of Ricerca Security, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-06-30 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceSearchable Japan records
Reflected cross-site scripting vulnerability in multiple laser printers and MFPs which implement Ricoh Web Image Monitor
Web Image Monitor provided by Ricoh Company, Ltd. is a web server that is included in and runs on laser printers and MFPs (multifunction printers). Web Image Monitor contains the vulnerability listed below. Reflected cross-site scripting (CWE-79) - CVE-2026-56809 Tomasz Holeksa of Pentest Limited reported this vulnerability to Ricoh Company, Ltd. directly and coordinated. After the coordination, Ricoh Company, Ltd...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Multiple vulnerabilities in the installer for Pupsman
The installer for Pupsman provided by Fuji Electric Co.,Ltd. contains multiple vulnerabilities listed below: Uncontrolled search path element (CWE-427) - CVE-2026-56437 The CVSS vectors above assume that a victim user is directed to place a specially crafted DLL file in the same folder as the affected installer and to execute the installer. Incorrect default permissions (CWE-276) - CVE-2026-57895 Kazuma Matsumoto ...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
SEIKO EPSON printers and scanners Web Config vulnerable to cross-site request forgery
Web Config embedded in multiple printers and scanners provided by SEIKO EPSON CORPORATION contains the following vulnerability. Cross-site request forgery (CWE-352) - CVE-2026-58315 Kentaro Ishii of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Seiko Solutions SkyBridge MB-A100/MB-A110 vulnerable to OS command injection
SkyBridge MB-A100/MB-A110 provided by Seiko Solutions Inc. contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-50043 Takeshi Kuramori and Kaori Takashima of National Institute of Information and Communications Technology, Cybersecurity Research Institute reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
RPG MAKER MV and MZ vulnerable to OS command injection
RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. are game development tools, which provide "save data" facility to create a file to preserve game status and related parameters. A user can save the current game status to a save-file, and later load the file to resume playing the game. When loading a save-file, RPG MAKER MV and MZ fail to properly treat crafted contents, and may lead to OS command injection....
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
DGM3103SCT vulnerable to OS command injection
DGM3103SCT provided by AVTECH Security Corporation contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-56808 Tomoya KITAGAWA, Satoki TSUJI, Seiya NAKATA, and Yudai FUJIWARA of Ricerca Security, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in Fluentd
Fluentd provided by Fluentd Project contains multiple vulnerabilities listed below. Path traversal in ${tag} Placeholder (CWE-22) - CVE-2026-44024 Missing authentication for critical function in Monitor Agent API (CWE-306) - CVE-2026-44025 Improper handling of highly compressed data in in_http and in_forward (CWE-409) - CVE-2026-44160 Server-side request forgery in out_http (CWE-918) - CVE-2026-44161 Improper hand...
- Entity
- JVN iPedia
- Sector
- cloud-infrastructure
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
ExpressUpdate Agent for Windows improper access restriction on its named pipe
ExpressUpdate Agent for Windows provided by NEC Corporation is the software module for NEC server products, to support remote management of installed software. ExpressUpdate Agent for Windows configures its named pipe with an improper access restriction. Exposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-8797 MASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated ...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Generic IO & Memory Access driver for TOSHIBA and Dynabook PCs exposes its IOCTL with insufficient access control
Generic IO & Memory Access driver is part of a utility to configure BIOS/Supervisor passwords from within Windows. This driver is installed on PCs provided by TOSHIBA CORPORATION and Dynabook Inc. between 2009 and 2016. The driver contains the following vulnerability. Exposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-56129 The CVSS assessment above assumes that a user with no administrative privi...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple Vulnerabilities in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer, Hitachi Ops Center Analyzer viewpoint and Hitachi Ops Center Viewpoint
Hitachi Infrastructure Analytics Advisor contains the following vulnerability: CVE-2025-48924 Hitachi Ops Center Analyzer contains the following vulnerabilities: CVE-2025-48924 Hitachi Ops Center Analyzer viewpoint contains the following vulnerability: CVE-2025-48924 Hitachi Ops Center Viewpoint contains the following vulnerabilities: CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, ...
- Entity
- JVN iPedia
- Sector
- operational-technology
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in Canon EOS Network Setting Tool
FTP/FTPS/SFTP Communication Testing features of PC Software EOS Network Setting Tool provided by Canon Inc. contain multiple vulnerabilities listed below. Improper validation of SSH host key (CWE-295) - CVE-2026-9258 Improper validation of server certificate (CWE-295) - CVE-2026-9259 Use of hard-coded cryptographic key (CWE-321) - CVE-2026-9260 Use of a vulnerable SSH encryption algorithm (CWE-327) - CVE-2026-9261...
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
OS command injection in RadiX AX6600 WiFi 6 Tri-Band Gaming Router
RadiX AX6600 WiFi 6 Tri-Band Gaming Router provided by Micro-Star International Co., Ltd. contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-53876 KAZUHIRO SHIBUTA of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Improper file access permission settings in the installers for Optical Disc Archive Software for Windows
Optical Disc Archive Software for Windows provided by Sony Corporation contains the following vulnerability. Incorrect default permissions (CWE-276) - CVE-2026-50255 Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
ThingsBoard vulnerable to prototype pollution
ThingsBoard contains the following vulnerability Prototype Pollution (CWE-1321) - CVE-2026-53676 HIROKI IMAI of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Privilege escalation vulnerability in multiple RICOH and KONICA MINOLTA JAPAN printer drivers
Multiple printer drivers provided by RICOH and KONICA MINOLTA JAPAN contain the following vulnerability: Privilege escalation (CWE-427) - CVE-2026-50100 Ricoh Company, Ltd. reported this vulnerability to IPA to notify users of its solution through JVN. JPCERT/CC and Ricoh Company, Ltd. coordinated under the Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Mitigation for iSCSI Port Vulnerability in Hitachi Disk Array Systems
When a large number of malicious packets are received, the iSCSI port may become unresponsive. (CVE-2025-7737)
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Vulnerability in Cosminexus HTTP Server and Hitachi Web Server
Vulnerability has been found in Cosminexus HTTP Server and Hitachi Web Server. CVE-2025-65082 This vulnerability will not occur if CGI is not used.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
CamView installer insecurely loads Dynamic Link Libraries
CamView installer provided by ARUCOM Inc. insecurely loads Dynamic Link Libraries. Uncontrolled search path element (CWE-427) - CVE-2015-9268 The CVSS evaluation above assume that a victim user is directed to download and place a specially crafted DLL file with the affected installer and to execute the installer. Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coo...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Multiple TP-Link products vulnerable to cleartext transmission of sensitive information
Multiple TP-Link products provided by TP-Link Systems Inc. contain the following vulnerability. Cleartext transmission of sensitive information (CWE-319) - CVE-2026-34126 eyegrep and izurina of L Plus LLC reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Security information for Hitachi Disk Array Systems
CVE-2026-0390 | UEFI Secure Boot Security Feature Bypass Vulnerability CVE-2026-20806 | Windows COM Server Information Disclosure Vulnerability CVE-2026-20928 | Windows Recovery Environment Security Feature Bypass Vulnerability CVE-2026-20930 | Windows Management Services Elevation of Privilege Vulnerability CVE-2026-23666 | .NET Framework Denial of Service Vulnerability CVE-2026-23670 | Windows Virtualization-Bas...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
TP-Link Archer BE450 and BE7200 vulnerable to OS command injection
Archer BE450 and BE7200 provided by TP-Link contain the following vulnerability. OS command injection (CWE-78) - CVE-2026-5509 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
WordPress Plugin "Zoho Mail for WordPress" vulnerable to cross-site request forgery
WordPress Plugin "Zoho Mail for WordPress" provided by Zoho Corporation contains the following vulnerability. Cross-site request forgery (CWE-352) - CVE-2026-8174 Norio Abe reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Link following vulnerability in Canon My Image Garden for macOS and CUPS Printer Driver for macOS
My Image Garden for MacOS and CUPS Printer Driver for macOS provided by Canon Inc. contain the following vulnerability. Improper link resolution before file access ('Link following') (CWE-59) - CVE-2026-6891, CVE-2026-6892 Canon Inc. reported this vulnerability to JPCERT/CC to notify users of the solutions through JVN.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Multiple vulnerabilities in ServerView Agents for Windows
ServerView Agents for Windows provided by Fsas Technologies Inc. is server management software. ServerView Agents for Windows contains multiple vulnerabilities listed below. Incorrect permission assignment for critical resource (CWE-732) - CVE-2026-27788 Privilege chaining (CWE-268) - CVE-2026-32325 MASAHIRO IIDA of LAC Co., Ltd. reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia