Topic Collection / Japan Vulnerability Records
Japan Vulnerability Signals
Official JVN iPedia records, guarded JPCERT/CC alert records, guarded IPA icat security-alert records, and NISC/NCO national-warning notices, normalized into an English-first monitoring layer for Japanese supplier, product, CVE, CERT advisory, and national cyber-warning review. Records enter the database before any article decision.
Server-Rendered Database Proof
Japan records are counted before browser hydration.
This collection renders database totals, source-family counts, freshness, and export links from the public summary first. The browser then loads a capped record list for interactive search.
Summary generated 2026-07-27 11:12. If the record list is still loading, these server-side counts remain the collection baseline.
Source Status
Core Japan vulnerability, CERT, and NISC layer
Japan JVN latest polling/backfill, scheduled JPCERT/CC alert polling/backfill, guarded scheduled IPA icat latest polling, and guarded NISC/NCO public-warning records are active. Monthly vendor patch-cycle and broad policy/reference rows remain review-only.
The database has active monitoring records for this collection. A quiet period means the source did not publish matching records, not that the page is broken.
What this collection covers
JVN iPedia records identify affected products, CVEs, weakness types, vendors, reporting organizations, and remediation context. JPCERT/CC alerts, IPA icat security-alert rows, and NISC/NCO public warnings add official Japan CERT/government prioritization for selected security alerts, campaign warnings, ransomware/DDoS guidance, and national cyber-warning context. Nogosee stores them as monitoring records so teams can search Japan exposure without turning every source note into a thin article.
Collection status
The latest JVN feed is active, official yearly JVN backfill is running in small newest-to-oldest segments, JPCERT/CC alert coverage is scheduled, IPA icat latest polling is guarded by D1 overlap checks, and NISC/NCO warning-list rows are guarded/manual with explicit allowlists. Japan remains focused on vulnerability, CERT, and national-warning depth before broader Japan procurement expansion.
Enterprise Handoff
Turn this public slice into a monitored workflow
Start with capped public records for Japan Vulnerability Signals, then request the minimum private access needed for repeat review, team routing, or historical analysis.
Evaluate The Slice
Open the tracker preset and capped CSV first, then request a bounded evaluation export only if the public view fits your review queue.
Open tracker presetDownload capped CSVRequest evaluation exportAutomate Monitoring
Use the public RSS feed for lightweight follow-up, or request recurring feed/API access for SIEM, vendor-risk, and internal dashboard workflows.
Open RSS feedRequest recurring feedRequest API integrationScope Team Access
Ask for historical export or custom monitoring when a team needs country, sector, source-family, entity, or threat-theme coverage beyond public caps.
Request historical exportRequest team monitoring setupPublic pages prove workflow fit without exposing private source baskets, full historical archives, scoring weights, matching logic, prompts, or anti-abuse controls.
Use this as a supplier exposure workflow
Search by CVE, product, vendor, weakness, CERT advisory, or sector. Open the official source for verification, then use the tracker preset or capped CSV sample for weekly review. Full data-feed access stays request-only.
537 rendered records. Public exports are capped; commercial feeds are available by request.
Highest-priority Japan signals
Ricoh printers and Multifunction Printers (MFPs) missing restriction on SSH port forwarding
Some series of printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. provide SSH service, but no restriction is implemented on SSH port forwarding. Improper restriction of communication channel to intended endpoints (CWE-923) - CVE-2026-63226 Brandon Roach and Bryan Clements of Pathfynder.io reported this vulnerability to Ricoh Company, Ltd. and coordinated. After the coordination was complete...
Published 2026-07-23 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceVulnerability in certain IC chips of contactless IC card "FeliCa"
For certain FeliCa IC chips shipped by Sony Corporation in or before 2017, a certain operation during cryptographic processing may compromise the intended security strength. Missing cryptographic step (CWE-325) - CVE-2026-59776 KIRISHIKI Yudai of Unknown Technologies Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-07-21 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceDrupal plugin "AI Agents" vulnerable to incorrect authorization
AI Agents provided by Drupal contains the vulnerability listed below. Incorrect authorization (CWE-863) - CVE-2026-13236 Kuniyoshi Noguchi @KuniNogu reported this vulnerability to the developer and IPA. JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.
Published 2026-07-21 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceSecurity information for Hitachi Disk Array Systems
CVE-2025-54518 | AMD: CVE-2025-54518 CPU OP Cache Corruption CVE-2026-21530 | Windows Rich Text Edit Elevation of Privilege Vulnerability CVE-2026-32161 | Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability CVE-2026-32170 | Windows Rich Text Edit Elevation of Privilege Vulnerability CVE-2026-32177 | .NET Elevation of Privilege Vulnerability CVE-2026-32209 | Windows Filtering Platform (WFP) Secu...
Published 2026-07-17 / Japan JVN iPedia / JVN iPedia / cloud-infrastructureMultiple vulnerabilities in TTSSH2 plugin of Tera Term
TTSSH2 plugin of Tera Term provided by TeraTerm Project contains the following vulnerabilities: Unsigned to Signed Conversion Error (CWE-196) - CVE-2026-58317 Improper Handling of Length Parameter Inconsistency (CWE-130) - CVE-2026-60060 CVE-2026-58317 Yukihiro Nakamura reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2026-60060 ...
Published 2026-07-16 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceInstaller of HYPER SBI 2 insecurely loads Dynamic Link Libraries
The installer of HYPER SBI 2 provided by SBI SECURITIES Co., Ltd. insecurely loads Dynamic Link Libraries. Uncontrolled search path element (CWE-427) - CVE-2026-42936 Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Published 2026-07-15 / Japan JVN iPedia / JVN iPedia / vulnerability-intelligenceSearchable Japan records
Ricoh printers and Multifunction Printers (MFPs) missing restriction on SSH port forwarding
Some series of printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. provide SSH service, but no restriction is implemented on SSH port forwarding. Improper restriction of communication channel to intended endpoints (CWE-923) - CVE-2026-63226 Brandon Roach and Bryan Clements of Pathfynder.io reported this vulnerability to Ricoh Company, Ltd. and coordinated. After the coordination was complete...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Vulnerability in certain IC chips of contactless IC card "FeliCa"
For certain FeliCa IC chips shipped by Sony Corporation in or before 2017, a certain operation during cryptographic processing may compromise the intended security strength. Missing cryptographic step (CWE-325) - CVE-2026-59776 KIRISHIKI Yudai of Unknown Technologies Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Drupal plugin "AI Agents" vulnerable to incorrect authorization
AI Agents provided by Drupal contains the vulnerability listed below. Incorrect authorization (CWE-863) - CVE-2026-13236 Kuniyoshi Noguchi @KuniNogu reported this vulnerability to the developer and IPA. JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-7-days
Security information for Hitachi Disk Array Systems
CVE-2025-54518 | AMD: CVE-2025-54518 CPU OP Cache Corruption CVE-2026-21530 | Windows Rich Text Edit Elevation of Privilege Vulnerability CVE-2026-32161 | Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability CVE-2026-32170 | Windows Rich Text Edit Elevation of Privilege Vulnerability CVE-2026-32177 | .NET Elevation of Privilege Vulnerability CVE-2026-32209 | Windows Filtering Platform (WFP) Secu...
- Entity
- JVN iPedia
- Sector
- cloud-infrastructure
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in TTSSH2 plugin of Tera Term
TTSSH2 plugin of Tera Term provided by TeraTerm Project contains the following vulnerabilities: Unsigned to Signed Conversion Error (CWE-196) - CVE-2026-58317 Improper Handling of Length Parameter Inconsistency (CWE-130) - CVE-2026-60060 CVE-2026-58317 Yukihiro Nakamura reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2026-60060 ...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries
The installer of HYPER SBI 2 provided by SBI SECURITIES Co., Ltd. insecurely loads Dynamic Link Libraries. Uncontrolled search path element (CWE-427) - CVE-2026-42936 Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Denial-of-service (DoS) vulnerability in the in-app browser of LINE client for iOS
LINE client for iOS provided by LY Corporation contains a vulnerability in the in-app browser due to insufficient safeguards when handling arbitrary URL schemes, which may lead to denial-of-service (DoS) condition (CWE-400, CVE-2026-3861). LY Corporation reported this vulnerability to JPCERT/CC to notify users of its solution through JVN.
- Entity
- JVN iPedia
- Sector
- mobile-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Reflected cross-site scripting vulnerability in multiple laser printers and MFPs which implement Ricoh Web Image Monitor
Web Image Monitor provided by Ricoh Company, Ltd. is a web server that is included in and runs on laser printers and MFPs (multifunction printers). Web Image Monitor contains the vulnerability listed below. Reflected cross-site scripting (CWE-79) - CVE-2026-56809 Tomasz Holeksa of Pentest Limited reported this vulnerability to Ricoh Company, Ltd. directly and coordinated. After the coordination, Ricoh Company, Ltd...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in the installer for Pupsman
The installer for Pupsman provided by Fuji Electric Co.,Ltd. contains multiple vulnerabilities listed below: Uncontrolled search path element (CWE-427) - CVE-2026-56437 The CVSS vectors above assume that a victim user is directed to place a specially crafted DLL file in the same folder as the affected installer and to execute the installer. Incorrect default permissions (CWE-276) - CVE-2026-57895 Kazuma Matsumoto ...
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
SEIKO EPSON printers and scanners Web Config vulnerable to cross-site request forgery
Web Config embedded in multiple printers and scanners provided by SEIKO EPSON CORPORATION contains the following vulnerability. Cross-site request forgery (CWE-352) - CVE-2026-58315 Kentaro Ishii of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Seiko Solutions SkyBridge MB-A100/MB-A110 vulnerable to OS command injection
SkyBridge MB-A100/MB-A110 provided by Seiko Solutions Inc. contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-50043 Takeshi Kuramori and Kaori Takashima of National Institute of Information and Communications Technology, Cybersecurity Research Institute reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
RPG MAKER MV and MZ vulnerable to OS command injection
RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. are game development tools, which provide "save data" facility to create a file to preserve game status and related parameters. A user can save the current game status to a save-file, and later load the file to resume playing the game. When loading a save-file, RPG MAKER MV and MZ fail to properly treat crafted contents, and may lead to OS command injection....
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
DGM3103SCT vulnerable to OS command injection
DGM3103SCT provided by AVTECH Security Corporation contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-56808 Tomoya KITAGAWA, Satoki TSUJI, Seiya NAKATA, and Yudai FUJIWARA of Ricerca Security, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
Multiple vulnerabilities in Fluentd
Fluentd provided by Fluentd Project contains multiple vulnerabilities listed below. Path traversal in ${tag} Placeholder (CWE-22) - CVE-2026-44024 Missing authentication for critical function in Monitor Agent API (CWE-306) - CVE-2026-44025 Improper handling of highly compressed data in in_http and in_forward (CWE-409) - CVE-2026-44160 Server-side request forgery in out_http (CWE-918) - CVE-2026-44161 Improper hand...
- Entity
- JVN iPedia
- Sector
- cloud-infrastructure
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia, fresh-within-30-days
ExpressUpdate Agent for Windows improper access restriction on its named pipe
ExpressUpdate Agent for Windows provided by NEC Corporation is the software module for NEC server products, to support remote management of installed software. ExpressUpdate Agent for Windows configures its named pipe with an improper access restriction. Exposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-8797 MASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated ...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Generic IO & Memory Access driver for TOSHIBA and Dynabook PCs exposes its IOCTL with insufficient access control
Generic IO & Memory Access driver is part of a utility to configure BIOS/Supervisor passwords from within Windows. This driver is installed on PCs provided by TOSHIBA CORPORATION and Dynabook Inc. between 2009 and 2016. The driver contains the following vulnerability. Exposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-56129 The CVSS assessment above assumes that a user with no administrative privi...
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Multiple Vulnerabilities in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer, Hitachi Ops Center Analyzer viewpoint and Hitachi Ops Center Viewpoint
Hitachi Infrastructure Analytics Advisor contains the following vulnerability: CVE-2025-48924 Hitachi Ops Center Analyzer contains the following vulnerabilities: CVE-2025-48924 Hitachi Ops Center Analyzer viewpoint contains the following vulnerability: CVE-2025-48924 Hitachi Ops Center Viewpoint contains the following vulnerabilities: CVE-2023-35116, CVE-2025-24970, CVE-2025-25193, CVE-2025-48924, CVE-2025-55163, ...
- Entity
- JVN iPedia
- Sector
- operational-technology
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Multiple vulnerabilities in Canon EOS Network Setting Tool
FTP/FTPS/SFTP Communication Testing features of PC Software EOS Network Setting Tool provided by Canon Inc. contain multiple vulnerabilities listed below. Improper validation of SSH host key (CWE-295) - CVE-2026-9258 Improper validation of server certificate (CWE-295) - CVE-2026-9259 Use of hard-coded cryptographic key (CWE-321) - CVE-2026-9260 Use of a vulnerable SSH encryption algorithm (CWE-327) - CVE-2026-9261...
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
OS command injection in RadiX AX6600 WiFi 6 Tri-Band Gaming Router
RadiX AX6600 WiFi 6 Tri-Band Gaming Router provided by Micro-Star International Co., Ltd. contains the following vulnerability. OS command injection (CWE-78) - CVE-2026-53876 KAZUHIRO SHIBUTA of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- network-and-edge-devices
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Improper file access permission settings in the installers for Optical Disc Archive Software for Windows
Optical Disc Archive Software for Windows provided by Sony Corporation contains the following vulnerability. Incorrect default permissions (CWE-276) - CVE-2026-50255 Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
ThingsBoard vulnerable to prototype pollution
ThingsBoard contains the following vulnerability Prototype Pollution (CWE-1321) - CVE-2026-53676 HIROKI IMAI of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Privilege escalation vulnerability in multiple RICOH and KONICA MINOLTA JAPAN printer drivers
Multiple printer drivers provided by RICOH and KONICA MINOLTA JAPAN contain the following vulnerability: Privilege escalation (CWE-427) - CVE-2026-50100 Ricoh Company, Ltd. reported this vulnerability to IPA to notify users of its solution through JVN. JPCERT/CC and Ricoh Company, Ltd. coordinated under the Information Security Early Warning Partnership.
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Mitigation for iSCSI Port Vulnerability in Hitachi Disk Array Systems
When a large number of malicious packets are received, the iSCSI port may become unresponsive. (CVE-2025-7737)
- Entity
- JVN iPedia
- Sector
- vulnerability-intelligence
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia
Vulnerability in Cosminexus HTTP Server and Hitachi Web Server
Vulnerability has been found in Cosminexus HTTP Server and Hitachi Web Server. CVE-2025-65082 This vulnerability will not occur if CGI is not used.
- Entity
- JVN iPedia
- Sector
- enterprise-software
- Scoring reasons
- public-vulnerability-record, japan-jvn-ipedia