Topic Collection / Japan Vulnerability Records
Japan Vulnerability Signals
Official JVN iPedia records, guarded JPCERT/CC alert records, guarded IPA icat security-alert records, and NISC/NCO national-warning notices, normalized into an English-first monitoring layer for Japanese supplier, product, CVE, CERT advisory, and national cyber-warning review. Records enter the database before any article decision.
Server-Rendered Database Proof
Japan records are counted before browser hydration.
This collection renders database totals, source-family counts, freshness, and export links from the public summary first. The browser then loads a capped record list for interactive search.
Summary generated 2026-08-16 12:17. If the record list is still loading, these server-side counts remain the collection baseline.
Source Status
Core Japan vulnerability, CERT, and NISC layer
Japan JVN latest polling/backfill, scheduled JPCERT/CC alert polling/backfill, guarded scheduled IPA icat latest polling, and guarded NISC/NCO public-warning records are active. Monthly vendor patch-cycle and broad policy/reference rows remain review-only.
The database has active monitoring records for this collection. A quiet period means the source did not publish matching records, not that the page is broken.
What this collection covers
JVN iPedia records identify affected products, CVEs, weakness types, vendors, reporting organizations, and remediation context. JPCERT/CC alerts, IPA icat security-alert rows, and NISC/NCO public warnings add official Japan CERT/government prioritization for selected security alerts, campaign warnings, ransomware/DDoS guidance, and national cyber-warning context. Nogosee stores them as monitoring records so teams can search Japan exposure without turning every source note into a thin article.
Collection status
The latest JVN feed is active, official yearly JVN backfill is running in small newest-to-oldest segments, JPCERT/CC alert coverage is scheduled, IPA icat latest polling is guarded by D1 overlap checks, and NISC/NCO warning-list rows are guarded/manual with explicit allowlists. Japan remains focused on vulnerability, CERT, and national-warning depth before broader Japan procurement expansion.
Enterprise Handoff
Turn this public slice into a monitored workflow
Start with capped public records for Japan Vulnerability Signals, then request the minimum private access needed for repeat review, team routing, or historical analysis.
Evaluate The Slice
Open the tracker preset and capped CSV first, then request a bounded evaluation export only if the public view fits your review queue.
Open tracker presetDownload capped CSVRequest evaluation exportAutomate Monitoring
Use the public RSS feed for lightweight follow-up, or request recurring feed/API access for SIEM, vendor-risk, and internal dashboard workflows.
Open RSS feedRequest recurring feedRequest API integrationScope Team Access
Ask for historical export or custom monitoring when a team needs country, sector, source-family, entity, or threat-theme coverage beyond public caps.
Request historical exportRequest team monitoring setupPublic pages prove workflow fit without exposing private source baskets, full historical archives, scoring weights, matching logic, prompts, or anti-abuse controls.
Use this as a supplier exposure workflow
Search by CVE, product, vendor, weakness, CERT advisory, or sector. Open the official source for verification, then use the tracker preset or capped CSV sample for weekly review. Full data-feed access stays request-only.
558 rendered records. Public exports are capped; commercial feeds are available by request.
Highest-priority Japan signals
VoiceTra vulnerable to incorrectly specified destination in a communication channel
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains the following vulnerability. Incorrectly specified destination in a communication channel (CWE-941) - CVE-2026-72506 RyotaK of GMO Flatt Security Inc. reported this vulnerability to NICT and coordinated. After the coordination was completed, RyotaK reported the case to JPCERT/CC to notify users of the solution thro...
Published 2026-08-13 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceInstaller for LINE for Windows insecurely loads Dynamic Link Libraries
The installer for LINE for Windows provided by LY Corporation contains the following vulnerability: Uncontrolled search path element (CWE-427) - CVE-2026-13133 The CVSS evaluation above assumes that a victim user is directed to download and place a specially crafted DLL file alongside the affected installer and then invoke the installer. Yukihiro Nakamura reported this vulnerability to IPA. JPCERT/CC coordinated w...
Published 2026-08-10 / Japan JVN iPedia / JVN iPedia / enterprise-softwareMultiple vulnerabilities in NetKids iMark
NetKids iMark provided by Integrated Systems Technologies, Inc. contains multiple vulnerabilities listed below: Uncontrolled search path element (CWE-427) - CVE-2026-66344 Unquoted search path or element (CWE-428) - CVE-2026-66839 Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-08-05 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceMultiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc. web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403 Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404 telnet server remains enabled (CWE-489) - CVE-202...
Published 2026-08-05 / Japan JVN iPedia / JVN iPedia / network-and-edge-devicesVulnerability in Cosminexus HTTP Server
Vulnerability(CVE-2026-49975) has been found in Cosminexus HTTP Server. This vulnerability does not apply if HTTP/2 protocol is disabled.
Published 2026-08-05 / Japan JVN iPedia / JVN iPedia / enterprise-softwareVulnerability in Cosminexus HTTP Server
Vulnerability(CVE-2026-48913) has been found in Cosminexus HTTP Server. This vulnerability does not apply if HTTP/2 protocol is disabled.
Published 2026-08-05 / Japan JVN iPedia / JVN iPedia / enterprise-softwareSearchable Japan records
VoiceTra vulnerable to incorrectly specified destination in a communication channel
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains the following vulnerability. Incorrectly specified destination in a communication channel (CWE-941) - CVE-2026-72506 RyotaK of GMO Flatt Security Inc. reported this vulnerability to NICT and coordinated. After the coordination was completed, RyotaK reported the case to JPCERT/CC to notify users of the solution thro...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Installer for LINE for Windows insecurely loads Dynamic Link Libraries
The installer for LINE for Windows provided by LY Corporation contains the following vulnerability: Uncontrolled search path element (CWE-427) - CVE-2026-13133 The CVSS evaluation above assumes that a victim user is directed to download and place a specially crafted DLL file alongside the affected installer and then invoke the installer. Yukihiro Nakamura reported this vulnerability to IPA. JPCERT/CC coordinated w...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Multiple vulnerabilities in NetKids iMark
NetKids iMark provided by Integrated Systems Technologies, Inc. contains multiple vulnerabilities listed below: Uncontrolled search path element (CWE-427) - CVE-2026-66344 Unquoted search path or element (CWE-428) - CVE-2026-66839 Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Robotic cleaners DEEBOT PRO M1 and DEEBOT PRO K1VAC, and mobile app ECOVACS PRO App developed by ECOVACS ROBOTICS contain multiple vulnerabilities. They are provided in Japan by Hellohas Robotics Inc. web server for debugging purposes remains enabled (CWE-489) - CVE-2026-66403 Missing server certificate verification in MQTT communications (CWE-295) - CVE-2026-66404 telnet server remains enabled (CWE-489) - CVE-202...
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Vulnerability in Cosminexus HTTP Server
Vulnerability(CVE-2026-49975) has been found in Cosminexus HTTP Server. This vulnerability does not apply if HTTP/2 protocol is disabled.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Vulnerability in Cosminexus HTTP Server
Vulnerability(CVE-2026-48913) has been found in Cosminexus HTTP Server. This vulnerability does not apply if HTTP/2 protocol is disabled.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Vulnerability in Cosminexus HTTP Server and Hitachi Web Server
Vulnerability(CVE-2026-43951) has been found in Cosminexus HTTP Server and Hitachi Web Server.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple Vulnerabilities in Hitachi Ops Center Common Services
Multiple vulnerabilities exist in Hitachi Ops Center Common Services. CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-202...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Vulnerability in Cosminexus HTTP Server and Hitachi Web Server
Vulnerability(CVE-2026-33523) has been found in Cosminexus HTTP Server and Hitachi Web Server.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
freo2 vulnerable to unrestricted upload of file with dangerous type
freo2 provided by refirio is a content management system written in PHP. freo2 contains the following vulnerability. Unrestricted upload of file with dangerous type (CWE-434) - CVE-2026-67243 Kazuki Ozawa of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
CSV file injection vulnerability in BaserCMS
BaserCMS provided by baserCMS Users Community contains the following vulnerability. Improper neutralization of formula elements in a CSV file (CWE-1236) - CVE-2026-65875 This vulnerability was reported by the following persons to JPCERT/CC. JPCERT/CC coordinated with the developer. VCSLab - Viettel Cyber Security quanlna2 (Le Nguyen Anh Quan) VCSLab - Viettel Cyber Security namdi (Do Ich Nam) VCSLab - Viettel Cybe...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Sharp Network Scanner Tool insecure initial configuration
Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation are Windows applications which work as FTP servers and accept scan outputs from MFPs. With the initial configuration, anyone can upload files unlimitedly without authentication. Initialization of a Resource with an Insecure Default (CWE-1188) - CVE-2026-62416 Deniz Güney Yıldırım reported this vulnerability to Sharp Corporation and co...
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in Sharp and Toshiba Tec MFPs
Sharp and Toshiba Tec MFPs (multifunction printers) contain multiple vulnerabilities listed below. User authentication can be bypassed with crafted URLs (CWE-425) - CVE-2026-60011 Incomplete cleanup of cached files (CWE-459) - CVE-2026-63545 Insecure initial configuration (CWE-1188) - CVE-2026-63563 The products for a certain market have been shipped with the user authentication feature disabled in the initial con...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Cybozu Garoon vulnerable to cross-site scripting
Scheduler in Cybozu Garoon provided by Cybozu, Inc contains the following vulnerability: Cross-Site Scripting (CWE-79) - CVE-2026-57279 CyCDB-4148 Cybozu, Inc reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Cybozu, Inc coordinated under the Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Security Update for Trend Micro Trend Vision One (July 2026)
Trend Micro Incorporated has released a security update for TrendAI Vision One Service Gateway. Trend Micro Incorporated reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Permissive regular expression vulnerability in Tegalog -Fumy Otegaru Memo Logger-
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains the following vulnerability: Permissive Regular Expression (CWE-625) - CVE-2026-64940 Yuji Tounai of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in ELECOM wireless LAN routers and access points (July 2026)
Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities listed below. Reflected cross-site scripting in WebUI (CWE-79) - CVE-2026-44387 OS command injection in WebUI (CWE-78) - CVE-2026-59764 OS command injection in Restore Settings (CWE-78) - CVE-2026-61376 CVE-2026-44387 Kentaro Ishii of GMO Cybersecurity by Ierae, Inc. reported this vulnerability to IPA. JPCE...
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
SEIKO EPSON printers and scanners Web Config vulnerable to cross-site request forgery
Web Config embedded in multiple printers and scanners provided by SEIKO EPSON CORPORATION contains the following vulnerability. Cross-site request forgery (CWE-352) - CVE-2026-58315 Kentaro Ishii of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Ricoh printers and Multifunction Printers (MFPs) missing restriction on SSH port forwarding
Some series of printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. provide SSH service, but no restriction is implemented on SSH port forwarding. Improper restriction of communication channel to intended endpoints (CWE-923) - CVE-2026-63226 Brandon Roach and Bryan Clements of Pathfynder.io reported this vulnerability to Ricoh Company, Ltd. and coordinated. After the coordination was complete...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Vulnerability in certain IC chips of contactless IC card "FeliCa"
For certain FeliCa IC chips shipped by Sony Corporation in or before 2017, a certain operation during cryptographic processing may compromise the intended security strength. Missing cryptographic step (CWE-325) - CVE-2026-59776 KIRISHIKI Yudai of Unknown Technologies Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Drupal plugin "AI Agents" vulnerable to incorrect authorization
AI Agents provided by Drupal contains the vulnerability listed below. Incorrect authorization (CWE-863) - CVE-2026-13236 Kuniyoshi Noguchi @KuniNogu reported this vulnerability to the developer and IPA. JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Security information for Hitachi Disk Array Systems
CVE-2025-54518 | AMD: CVE-2025-54518 CPU OP Cache Corruption CVE-2026-21530 | Windows Rich Text Edit Elevation of Privilege Vulnerability CVE-2026-32161 | Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability CVE-2026-32170 | Windows Rich Text Edit Elevation of Privilege Vulnerability CVE-2026-32177 | .NET Elevation of Privilege Vulnerability CVE-2026-32209 | Windows Filtering Platform (WFP) Secu...
- Entity
- JVN iPedia
- Sector
- cloud-infrastructure
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Multiple vulnerabilities in TTSSH2 plugin of Tera Term
TTSSH2 plugin of Tera Term provided by TeraTerm Project contains the following vulnerabilities: Unsigned to Signed Conversion Error (CWE-196) - CVE-2026-58317 Improper Handling of Length Parameter Inconsistency (CWE-130) - CVE-2026-60060 CVE-2026-58317 Yukihiro Nakamura reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2026-60060 ...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries
The installer of HYPER SBI 2 provided by SBI SECURITIES Co., Ltd. insecurely loads Dynamic Link Libraries. Uncontrolled search path element (CWE-427) - CVE-2026-42936 Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia