<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:41:38.070635+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-02_vde-2026-011</id>
    <title>Advisory2026-02_VDE-2026-011 — CODESYS Control V3 - Untrusted boot application</title>
    <updated>2026-10-02T11:41:38.074671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups. While only the privileged Administrators and Developer groups are intended to load or debug applications on the controller, users in the restricted Service group are allowed to perform maintenance operations, including explicitly replacing the boot application.</p>
<p>In addition to access control, the CODESYS Control runtime system includes an optional application signing feature. When enabled, the controller executes only applications that have been validly signed by authorized developers. However, the CmpApp component of the CODESYS Control runtime systems allows Service‑group users to install a new boot application without requiring any cryptographic validation, if the application signing is not enforced.</p>
<p>As a result, users with Service‑level privileges can install arbitrary boot applications and gain control over the code executed on the controller.</p>
<p>Note: The user group "Service" is a predefined group within the CODESYS Control runtime system. If additional user groups have been created or if the permissions of predefined groups have been modified, then the term "Service" should be understood as a synonym for all groups and their users with no or only limited access rights to the "PlcLogic" object, in conjunction with "Add/Remove" or "Modify" permissions for the boot application files.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-02_vde-2026-011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04079</id>
    <title>bdu:2026-04079</title>
    <updated>2026-10-02T11:41:38.074737+00:00</updated>
    <content>bdu:2026-04079</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277089</id>
    <title>EUVD-2026-277089</title>
    <updated>2026-10-02T11:41:38.074755+00:00</updated>
    <content>EUVD-2026-277089</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277089"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41660</id>
    <title>fkie_cve-2025-41660</title>
    <updated>2026-10-02T11:41:38.074767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-41660"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-25xg-52c8-p9q8</id>
    <title>GHSA-25xg-52c8-p9q8</title>
    <updated>2026-10-02T11:41:38.074788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-25xg-52c8-p9q8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0832</id>
    <title>WID-SEC-W-2026-0832 — CODESYS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:41:38.074802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um beliebigen Programmcode auszuführen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0832"/>
  </entry>
</feed>
