Topic Collection / Japan Vulnerability Records
Japan Vulnerability Signals
Official JVN iPedia records, guarded JPCERT/CC alert records, guarded IPA icat security-alert records, and NISC/NCO national-warning notices, normalized into an English-first monitoring layer for Japanese supplier, product, CVE, CERT advisory, and national cyber-warning review. Records enter the database before any article decision.
Server-Rendered Database Proof
Japan records are counted before browser hydration.
This collection renders database totals, source-family counts, freshness, and export links from the public summary first. The browser then loads a capped record list for interactive search.
Summary generated 2026-06-10 03:59. If the record list is still loading, these server-side counts remain the collection baseline.
Source Status
Core Japan vulnerability, CERT, and NISC layer
Japan JVN latest polling/backfill, scheduled JPCERT/CC alert polling/backfill, guarded scheduled IPA icat latest polling, and guarded NISC/NCO public-warning records are active. Monthly vendor patch-cycle and broad policy/reference rows remain review-only.
The database has active monitoring records for this collection. A quiet period means the source did not publish matching records, not that the page is broken.
What this collection covers
JVN iPedia records identify affected products, CVEs, weakness types, vendors, reporting organizations, and remediation context. JPCERT/CC alerts, IPA icat security-alert rows, and NISC/NCO public warnings add official Japan CERT/government prioritization for selected security alerts, campaign warnings, ransomware/DDoS guidance, and national cyber-warning context. Nogosee stores them as monitoring records so teams can search Japan exposure without turning every source note into a thin article.
Collection status
The latest JVN feed is active, official yearly JVN backfill is running in small newest-to-oldest segments, JPCERT/CC alert coverage is scheduled, IPA icat latest polling is guarded by D1 overlap checks, and NISC/NCO warning-list rows are guarded/manual with explicit allowlists. Japan remains focused on vulnerability, CERT, and national-warning depth before broader Japan procurement expansion.
Enterprise Handoff
Turn this public slice into a monitored workflow
Start with capped public records for Japan Vulnerability Signals, then request the minimum private access needed for repeat review, team routing, or historical analysis.
Evaluate The Slice
Open the tracker preset and capped CSV first, then request a bounded evaluation export only if the public view fits your review queue.
Open tracker presetDownload capped CSVRequest evaluation exportAutomate Monitoring
Use the public RSS feed for lightweight follow-up, or request recurring feed/API access for SIEM, vendor-risk, and internal dashboard workflows.
Open RSS feedRequest recurring feedRequest API integrationScope Team Access
Ask for historical export or custom monitoring when a team needs country, sector, source-family, entity, or threat-theme coverage beyond public caps.
Request historical exportRequest team monitoring setupPublic pages prove workflow fit without exposing private source baskets, full historical archives, scoring weights, matching logic, prompts, or anti-abuse controls.
Use this as a supplier exposure workflow
Search by CVE, product, vendor, weakness, CERT advisory, or sector. Open the official source for verification, then use the tracker preset or capped CSV sample for weekly review. Full data-feed access stays request-only.
472 rendered records. Public exports are capped; commercial feeds are available by request.
Highest-priority Japan signals
Multiple TP-Link products vulnerable to cleartext transmission of sensitive information
Multiple TP-Link products provided by TP-Link Systems Inc. contain the following vulnerability. Cleartext transmission of sensitive information (CWE-319) - CVE-2026-34126 eyegrep and izurina of L Plus LLC reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-06-05 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceSecurity information for Hitachi Disk Array Systems
CVE-2026-0390 | UEFI Secure Boot Security Feature Bypass Vulnerability CVE-2026-20806 | Windows COM Server Information Disclosure Vulnerability CVE-2026-20928 | Windows Recovery Environment Security Feature Bypass Vulnerability CVE-2026-20930 | Windows Management Services Elevation of Privilege Vulnerability CVE-2026-23666 | .NET Framework Denial of Service Vulnerability CVE-2026-23670 | Windows Virtualization-Bas...
Published 2026-06-04 / Japan JVN iPedia / JVN iPedia / enterprise-softwareTP-Link Archer BE450 and BE7200 vulnerable to OS command injection
Archer BE450 and BE7200 provided by TP-Link contain the following vulnerability. OS command injection (CWE-78) - CVE-2026-5509 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.
Published 2026-06-03 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceWordPress Plugin "Zoho Mail for WordPress" vulnerable to cross-site request forgery
WordPress Plugin "Zoho Mail for WordPress" provided by Zoho Corporation contains the following vulnerability. Cross-site request forgery (CWE-352) - CVE-2026-8174 Norio Abe reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-06-03 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceLink following vulnerability in Canon My Image Garden for macOS and CUPS Printer Driver for macOS
My Image Garden for MacOS and CUPS Printer Driver for macOS provided by Canon Inc. contain the following vulnerability. Improper link resolution before file access ('Link following') (CWE-59) - CVE-2026-6891, CVE-2026-6892 Canon Inc. reported this vulnerability to JPCERT/CC to notify users of the solutions through JVN.
Published 2026-06-01 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceMultiple vulnerabilities in ServerView Agents for Windows
ServerView Agents for Windows provided by Fsas Technologies Inc. is server management software. ServerView Agents for Windows contains multiple vulnerabilities listed below. Incorrect permission assignment for critical resource (CWE-732) - CVE-2026-27788 Privilege chaining (CWE-268) - CVE-2026-32325 MASAHIRO IIDA of LAC Co., Ltd. reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under...
Published 2026-06-01 / Japan JVN iPedia / JVN iPedia / enterprise-softwareSearchable Japan records
Multiple TP-Link products vulnerable to cleartext transmission of sensitive information
Multiple TP-Link products provided by TP-Link Systems Inc. contain the following vulnerability. Cleartext transmission of sensitive information (CWE-319) - CVE-2026-34126 eyegrep and izurina of L Plus LLC reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Security information for Hitachi Disk Array Systems
CVE-2026-0390 | UEFI Secure Boot Security Feature Bypass Vulnerability CVE-2026-20806 | Windows COM Server Information Disclosure Vulnerability CVE-2026-20928 | Windows Recovery Environment Security Feature Bypass Vulnerability CVE-2026-20930 | Windows Management Services Elevation of Privilege Vulnerability CVE-2026-23666 | .NET Framework Denial of Service Vulnerability CVE-2026-23670 | Windows Virtualization-Bas...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
TP-Link Archer BE450 and BE7200 vulnerable to OS command injection
Archer BE450 and BE7200 provided by TP-Link contain the following vulnerability. OS command injection (CWE-78) - CVE-2026-5509 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
WordPress Plugin "Zoho Mail for WordPress" vulnerable to cross-site request forgery
WordPress Plugin "Zoho Mail for WordPress" provided by Zoho Corporation contains the following vulnerability. Cross-site request forgery (CWE-352) - CVE-2026-8174 Norio Abe reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Link following vulnerability in Canon My Image Garden for macOS and CUPS Printer Driver for macOS
My Image Garden for MacOS and CUPS Printer Driver for macOS provided by Canon Inc. contain the following vulnerability. Improper link resolution before file access ('Link following') (CWE-59) - CVE-2026-6891, CVE-2026-6892 Canon Inc. reported this vulnerability to JPCERT/CC to notify users of the solutions through JVN.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in ServerView Agents for Windows
ServerView Agents for Windows provided by Fsas Technologies Inc. is server management software. ServerView Agents for Windows contains multiple vulnerabilities listed below. Incorrect permission assignment for critical resource (CWE-732) - CVE-2026-27788 Privilege chaining (CWE-268) - CVE-2026-32325 MASAHIRO IIDA of LAC Co., Ltd. reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Jupyter Server vulnerable to open redirect
Jupyter Server provided by Jupyter Development Team contains the vulnerability listed below. Open redirect (CWE-601) - CVE-2025-61669 Noriaki Iwasaki of Cyber Defense Institute, Inc. reported this vulnerability to IPA and the developer. JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint
Vulnerability has been found in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint.
- Entity
- JVN iPedia
- Sector
- operational-technology
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple Vulnerabilities in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center
Multiple vulnerabilities have been found in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center. CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282
- Entity
- JVN iPedia
- Sector
- operational-technology
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple Vulnerabilities in Cosminexus
Cosminexus Developer's Kit for Java(TM) and Hitachi Developer's Kit for Java contain the following vulnerabilities: CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
NEC Aterm series vulnerable to OS command injection (NV26-003)
NEC Aterm series products provided by NEC Corporation contain the following vulnerability. OS command injection (CWE-78) - CVE-2026-8652 So Kato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
NEC Aterm series vulnerable to cross-site scripting (NV26-002)
Aterm series products provided by NEC Corporation contain the following vulnerability. Cross-site scripting (CWE-79) - CVE-2026-6059 Noriaki Iwasaki of Cyber Defense Institute, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in Trend Micro Endpoint security products for enterprises (May 2026)
Multiple vulnerabilities in Trend Micro Endpoint security products for enterprises contain multiple vulnerabilities listed below. Relative path traversal in Apex One server (CWE-23) - CVE-2026-34926 The only product that could be vulnerable to this exploit is TrendAI Apex One (On Premise). Origin validation error in Security Agent (CWE-346) - CVE-2026-34927,CVE-2026-34928,CVE-2026-34929,CVE-2026-34930,CVE-2026-452...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Security information for Hitachi Disk Array Systems
CVE-2026-23667 | Broadcast DVR Elevation of Privilege Vulnerability CVE-2026-23668 | Windows Graphics Component Elevation of Privilege Vulnerability CVE-2026-23669 | Windows Print Spooler Remote Code Execution Vulnerability CVE-2026-23671 | Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability CVE-2026-23672 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vul...
- Entity
- JVN iPedia
- Sector
- operational-technology
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Android App "RoboForm Password Manager" insufficient validation of Android intents
Android App "RoboForm Password Manager" provided by Siber Systems, Inc. accepts intents from other applications to open relevant web pages (e.g., login pages), but without sufficient URL validation, user confirmation nor notification. Insufficient UI Warning of Dangerous Operations (CWE-357) - CVE-2026-47782 The CVSS vectors above assume that a victim user is directed to install some malicious app, and the app sen...
- Entity
- JVN iPedia
- Sector
- operational-technology
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Movable Type vulnerable to missing authorization
Movable Type provided by Six Apart Ltd. contains the following vulnerability. Missing authorization (CWE-862) - CVE-2026-44392 Six Apart Ltd. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Six Apart Ltd. coordinated under the Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in ELECOM wireless LAN routers and access points (May 2026)
Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities listed below. Use of Hard-coded Cryptographic Key in creating backup of configuration files (CWE-321) - CVE-2026-25107 OS command injection in processing of ping_ip_addr parameter (CWE-78) - CVE-2026-35506 Missing authentication when accepting in specific URLs (CWE-288) - CVE-2026-40621 OS command injection...
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
GUARDIANWALL MailSuite vulnerable to stack-based buffer overflow
GUARDIANWALL MailSuite provided by Canon Marketing Japan Inc. contains the following vulnerability. Stack-based buffer overflow in pop3wallpasswd command (CWE-121) - CVE-2026-32661 This can be exploited only when the product is configured to run pop3wallpasswd with grdnwww user privilege The developer states that attacks exploiting the vulnerability has been observed in GUARDIANWALL MailSuite (On-premises version)...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in "Musetheque V4 Information Disclosure for IPKNOWLEDGE"
Musetheque V4 Information Disclosure for IPKNOWLEDGE provided by Fujitsu Japan Limited contains multiple vulnerabilities listed below. Cross-site scripting (CWE-79) - CVE-2026-24662 Cross-site request forgery (CWE-352) - CVE-2026-28761 Nozomi Iimura, Sho Odagiri of GMO Cybersecurity by Ierae, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning ...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
WPS Office improper access restriction to its named pipe
WPS Office provided by WPS SOFTWARE PTE. LTD. contains a service program running background and providing certain functionalities to the other programs. This service program uses a named pipe to communicate with the other programs. The named pipe above is not properly protected and any non-administrative user can access it. Exposed dangerous method or function (CWE-749) - CVE-2018-6400 MASAHIRO IIDA of LAC Co., Lt...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Android App "Anshin Filter for au" vulnerable to cleartext transmission of sensitive information
Android App "Anshin Filter for au" provided by KDDI CORPORATION contains the following vulnerability. Cleartext transmission of sensitive information (CWE-319) - CVE-2026-41281
- Entity
- JVN iPedia
- Sector
- mobile-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Bytello Share (Windows Edition) installer executable insecurely loads Dynamic Link Libraries
GUARDIANWALL MailSuite provided by Canon Marketing Japan Inc. contains the following vulnerability. Stack-based buffer overflow in pop3wallpasswd command (CWE-121) - CVE-2026-32661 The developer states that attacks exploiting the vulnerability has been observed in GUARDIANWALL MailSuite (On-premises version). Canon Marketing Japan Inc. reported this vulnerability to JPCERT/CC to notify users of its solution throug...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Canon Production Printers and Office Multifunction Printers vulnerable to information disclosure
Canon Production Printers and Office Multifunction Printers contain the following vulnerability. Reliance on untrusted inputs in a security decision (CWE-807) - CVE-2026-1789 Canon Inc. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
"Kura Sushi Official App" vulnerable to improper certificate validation
"Kura Sushi Official App" provided by EPG, Inc. contains the following vulnerability. Improper certificate validation on push notifications (CWE-295) - CVE-2026-41872 This analysis assumes a man-in-the-middle attack being conducted with a malicious wireless LAN access point Tsuyoshi Ogawa of SAK University SIE Co., Ltd. reported this vulnerability to IPA.JPCERT/CC coordinated with the developer under Information S...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days