<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:14:02.833783+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-06322</id>
    <title>bdu:2026-06322</title>
    <updated>2026-10-03T18:14:02.959312+00:00</updated>
    <content>bdu:2026-06322</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-06322"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0537</id>
    <title>certfr-2026-avi-0537 — Une vulnérabilité a été découverte dans Palo Alto Networks User-ID Authentication Portal. Elle permet à un attaquant de…</title>
    <updated>2026-10-03T18:14:02.959352+00:00</updated>
    <content>certfr-2026-avi-0537</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336363</id>
    <title>EUVD-2026-336363</title>
    <updated>2026-10-03T18:14:02.959373+00:00</updated>
    <content>EUVD-2026-336363</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0300</id>
    <title>fkie_cve-2026-0300</title>
    <updated>2026-10-03T18:14:02.959385+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.</p>
<p>The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.</p>
<p>Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-0300"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3vfh-3cpw-2378</id>
    <title>GHSA-3vfh-3cpw-2378</title>
    <updated>2026-10-03T18:14:02.959424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.</p>
<p>The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.</p>
<p>Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3vfh-3cpw-2378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-139-02</id>
    <title>ICSA-26-139-02 — Siemens RUGGEDCOM APE1808 Devices</title>
    <updated>2026-10-03T18:14:02.959447+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to a dataplane interface A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially ex…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-139-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0132</id>
    <title>NCSC-2026-0132 — Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS</title>
    <updated>2026-10-03T18:14:02.959490+00:00</updated>
    <content>NCSC-2026-0132</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0132"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-967325</id>
    <title>SSA-967325 — SSA-967325: Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices</title>
    <updated>2026-10-03T18:14:02.959509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities.</p>
<p>Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks' upstream security notifications.</p>
<p>[1] https://security.paloaltonetworks.com/</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-967325"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1366</id>
    <title>WID-SEC-W-2026-1366 — Palo Alto Networks PAN-OS: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten</title>
    <updated>2026-10-03T18:14:02.959535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Palo Alto Networks PAN-OS ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1366"/>
  </entry>
</feed>
