<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:23:32.282309+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</id>
    <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-04T11:23:32.544591+00:00</updated>
    <content>certfr-2026-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj02810</id>
    <title>Withdrawn: CLEANSTART-2026-AJ02810 — Security fixes in kserve-modelmesh 0.12.0-r0</title>
    <updated>2026-10-04T11:23:32.544643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kserve-modelmesh</p>
<p>Package kserve-modelmesh version 0.12.0-r0 fixes 20 vulnerabilities: CVE-2026-24281, CVE-2026-24308, CVE-2026-33870, CVE-2026-33871, ghsa-7xrh-hqfc-g7qr...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-aj02810"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266294</id>
    <title>EUVD-2026-266294</title>
    <updated>2026-10-04T11:23:32.544723+00:00</updated>
    <content>EUVD-2026-266294</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1225</id>
    <title>fkie_cve-2026-1225</title>
    <updated>2026-10-04T11:23:32.544762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.</p>
<p>The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must  have write access to a 
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-1225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qqpg-mvqg-649v</id>
    <title>GHSA-qqpg-mvqg-649v — Logback allows an attacker to instantiate classes already present on the class path</title>
    <updated>2026-10-04T11:23:32.544804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: ch.qos.logback:logback-core</p>
<p>ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.</p>
<p>The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must  have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qqpg-mvqg-649v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10114-1</id>
    <title>openSUSE-SU-2026:10114-1 — logback-1.2.13-2.1 on GA media</title>
    <updated>2026-10-04T11:23:32.544845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>logback-1.2.13-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10114-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0361-1</id>
    <title>SUSE-SU-2026:0361-1 — Security update for logback</title>
    <updated>2026-10-04T11:23:32.544877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for logback</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0361-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1225</id>
    <title>UBUNTU-CVE-2026-1225</title>
    <updated>2026-10-04T11:23:32.544903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:Pro:22.04:LTS: logback, Ubuntu:24.04:LTS: logback, Ubuntu:25.10: logback, Ubuntu:26.04:LTS: logback</p>
<p>ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1225"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0202</id>
    <title>WID-SEC-W-2026-0202 — Logback: Schwachstelle ermöglicht Manipulation von Daten</title>
    <updated>2026-10-04T11:23:32.544952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Logback ausnutzen, um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0202"/>
  </entry>
</feed>
