<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent vulnerabilities from the ENISA CNA root</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Latest vulnerabilities published by the CNAs operating under the ENISA root of the CVE Program.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:13 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-103858 (CIRCL)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103858</link>
      <description>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</description>
      <content:encoded>MISP Incomplete Thread Authorization Allows Unauthorized Read and Post Access to Discussions</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103858</guid>
      <pubDate>Thu, 01 Oct 2026 11:31:32 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103664 (CIRCL)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103664</link>
      <description>MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter</description>
      <content:encoded>MISP Reflected Cross-Site Scripting via Unsanitized Analyst Data Seed Parameter</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103664</guid>
      <pubDate>Thu, 01 Oct 2026 08:55:51 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103662 (CIRCL)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103662</link>
      <description>MISP Reflected XSS in Taxonomy Tag Confirmation Forms</description>
      <content:encoded>MISP Reflected XSS in Taxonomy Tag Confirmation Forms</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103662</guid>
      <pubDate>Thu, 01 Oct 2026 08:48:38 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103659 (CIRCL)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103659</link>
      <description>MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes</description>
      <content:encoded>MISP: Object Distribution ACL Bypass via Event Flattening Exposes Organisation-Only Attributes</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103659</guid>
      <pubDate>Thu, 01 Oct 2026 08:33:05 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103655 (CIRCL)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103655</link>
      <description>MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period</description>
      <content:encoded>MISP TOTP Code Replay Allows Duplicate Authentication Within Validity Period</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103655</guid>
      <pubDate>Thu, 01 Oct 2026 08:08:55 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-103651 (CIRCL)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-103651</link>
      <description>MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass</description>
      <content:encoded>MISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication Bypass</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-103651</guid>
      <pubDate>Thu, 01 Oct 2026 07:34:02 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-80275 (NCSC-FI)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-80275</link>
      <description>Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint</description>
      <content:encoded>Comelit 1456B gateway allows low priviledge user to overwrite installer password via unauthorized endpoint</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-80275</guid>
      <pubDate>Thu, 01 Oct 2026 05:51:37 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-80276 (NCSC-FI)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-80276</link>
      <description>Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface</description>
      <content:encoded>Comelit 1456B gateway exposes remote configuration password via unauthenticated management interface</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-80276</guid>
      <pubDate>Thu, 01 Oct 2026 05:51:21 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-102490 (DIVD)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-102490</link>
      <description>Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha</description>
      <content:encoded>Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-102490</guid>
      <pubDate>Wed, 30 Sep 2026 16:21:20 +0000</pubDate>
    </item>
    <item>
      <title>CVE-2026-102489 (DIVD)</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-102489</link>
      <description>Undisclosed RCE in Zammad v6.3 and higher</description>
      <content:encoded>Undisclosed RCE in Zammad v6.3 and higher</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-102489</guid>
      <pubDate>Wed, 30 Sep 2026 16:21:19 +0000</pubDate>
    </item>
  </channel>
</rss>
