<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:12:28.450871+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/7paa023732</id>
    <title>7PAA023732 — System 800xA affected by 3rd party component vulnerabilities</title>
    <updated>2026-10-03T19:12:28.544980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ABB is aware of public reports of vulnerabilities in 7-Zip version 18.5 and Microsoft Azure Data Studio version 1.32 included in the product versions listed as affected in the advisory.</p>
<p>The vulnerability in 7-Zip can be exploited if attacker gains control over the system and extracts a malicious file using this version of 7-Zip. Otherwise, the attacker must force the user to visit malicious websites or click links and extract the package through 7-zip.</p>
<p>Microsoft Azure Data Studio gets installed along with SQL Server Management Studio. An attacker who successfully exploits vulnerability in Microsoft Azure Data studio may compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. if the Authentication, Authorization and Accountability is not configured properly in the system. However, none of the products listed above uses Microsoft Azure Data Studio. Microsoft Azure Data Studio is automatically removed from the system from System 800xA 7.0 onwards.</p>
<p>These vulnerabilities may appear when the product media is scanned. However, they can only be ex-ploited if the vulnerable software is installed on the system. For this reason, it is strongly advised to uninstall outdated or vulnerable versions of third-party software immediately.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/7paa023732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-00670</id>
    <title>bdu:2025-00670</title>
    <updated>2026-10-03T19:12:28.545052+00:00</updated>
    <content>bdu:2025-00670</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-00670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-eq95920</id>
    <title>CLEANSTART-2025-EQ95920 — Security fix for CVE-2025-0411 applied in: 7zip 23.01-r0</title>
    <updated>2026-10-03T19:12:28.545070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: 7zip</p>
<p>Security vulnerability affects the 7zip package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-eq95920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-273293</id>
    <title>EUVD-2026-273293</title>
    <updated>2026-10-03T19:12:28.545095+00:00</updated>
    <content>EUVD-2026-273293</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-273293"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-0411</id>
    <title>fkie_cve-2025-0411</title>
    <updated>2026-10-03T19:12:28.545107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.</p>
<p>The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-0411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2pjx-wvcg-vhr8</id>
    <title>GHSA-2pjx-wvcg-vhr8</title>
    <updated>2026-10-03T19:12:28.545132+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.</p>
<p>The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2pjx-wvcg-vhr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-184-03</id>
    <title>ICSA-25-184-03 — Mitsubishi Electric MELSOFT Update Manager (Update B)</title>
    <updated>2026-10-03T19:12:28.545151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Mitsubishi Electric MELSOFT Update Manager is vulnerable to an Integer Underflow vulnerability in 7-zip, included in MELSOFT Update Manager, that could allow a local authenticated attacker to execute arbitrary code by getting an authorized user to decompress a specially crafted compressed file. As a result, the attacker may disclose, tamper with information, or cause a denial-of-service (DoS) condition on the product. Mitsubishi Electric MELSOFT Update Manager is vulnerable to a Protection Mechanism Failure vulnerability in 7-zip, included in MELSOFT Update Manager, that could allow a local authenticated attacker to execute arbitrary code by getting an authorized user to decompress a specially crafted compressed file. As a result, the attacker may disclose, tamper with information, or cause a denial-of-service (DoS) condition on the product.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-184-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-0411</id>
    <title>Withdrawn: UBUNTU-CVE-2025-0411</title>
    <updated>2026-10-03T19:12:28.545174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:24.04:LTS: p7zip</p>
<p>7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-0411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0129</id>
    <title>WID-SEC-W-2025-0129 — 7-Zip: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-03T19:12:28.545196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in 7-Zip ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0129"/>
  </entry>
</feed>
