<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/cna-root/ENISA/recent</id>
  <title>Most recent vulnerabilities from the ENISA CNA root</title>
  <updated>2026-10-02T07:10:13.153529+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Latest vulnerabilities published by the CNAs operating under the ENISA root of the CVE Program.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103858</id>
    <title>CVE-2026-103858 (CIRCL)</title>
    <updated>2026-10-01T11:31:32.840000+00:00</updated>
    <content>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103858"/>
    <summary>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</summary>
    <published>2026-10-01T11:31:32.840000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103664</id>
    <title>CVE-2026-103664 (CIRCL)</title>
    <updated>2026-10-01T08:55:51.589000+00:00</updated>
    <content>MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103664"/>
    <summary>MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter</summary>
    <published>2026-10-01T08:55:51.589000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103662</id>
    <title>CVE-2026-103662 (CIRCL)</title>
    <updated>2026-10-01T08:48:38.222000+00:00</updated>
    <content>MISP Reflected XSS in Taxonomy Tag Confirmation Forms</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103662"/>
    <summary>MISP Reflected XSS in Taxonomy Tag Confirmation Forms</summary>
    <published>2026-10-01T08:48:38.222000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103659</id>
    <title>CVE-2026-103659 (CIRCL)</title>
    <updated>2026-10-01T08:33:05.141000+00:00</updated>
    <content>MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103659"/>
    <summary>MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes</summary>
    <published>2026-10-01T08:33:05.141000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103655</id>
    <title>CVE-2026-103655 (CIRCL)</title>
    <updated>2026-10-01T08:08:55.013000+00:00</updated>
    <content>MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103655"/>
    <summary>MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period</summary>
    <published>2026-10-01T08:08:55.013000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-103651</id>
    <title>CVE-2026-103651 (CIRCL)</title>
    <updated>2026-10-01T07:34:02.597000+00:00</updated>
    <content>MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-103651"/>
    <summary>MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass</summary>
    <published>2026-10-01T07:34:02.597000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-80275</id>
    <title>CVE-2026-80275 (NCSC-FI)</title>
    <updated>2026-10-01T05:51:37.479000+00:00</updated>
    <content>Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-80275"/>
    <summary>Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint</summary>
    <published>2026-10-01T05:51:37.479000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-80276</id>
    <title>CVE-2026-80276 (NCSC-FI)</title>
    <updated>2026-10-01T05:51:21.716000+00:00</updated>
    <content>Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-80276"/>
    <summary>Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface</summary>
    <published>2026-10-01T05:51:21.716000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-102490</id>
    <title>CVE-2026-102490 (DIVD)</title>
    <updated>2026-09-30T16:21:20.601000+00:00</updated>
    <content>Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-102490"/>
    <summary>Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha</summary>
    <published>2026-09-30T16:21:20.601000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-102489</id>
    <title>CVE-2026-102489 (DIVD)</title>
    <updated>2026-09-30T16:21:19.937000+00:00</updated>
    <content>Undisclosed RCE in Zammad v6.3 and higher</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-102489"/>
    <summary>Undisclosed RCE in Zammad v6.3 and higher</summary>
    <published>2026-09-30T16:21:19.937000+00:00</published>
  </entry>
</feed>
