<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:59:40.057890+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/4jde002044</id>
    <title>4JDE002044 — dynovaPRO™ Reset Credentials Vulnerability</title>
    <updated>2026-10-02T12:59:40.174501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ABB is aware of public reports of a vulnerability in the product listed as affected in the advisory. An update has been deployed to the cloud system that resolves a publicly reported vulnerability in the product versions listed above.</p>
<p>An attacker who successfully exploited this vulnerability could take remote control of the product.</p>
<p>The vulnerability has been identified in the keycloak authentication component which is integrated into dynovaPRO™. The vulnerability exists in the 'Forgot Password' functionality and allows unauthenticated attackers to bypass authentication and hijack user accounts.</p>
<p>Users who have received a password reset mail before the mentioned date, without having requested it, are thereby potentially attacked by exploiting this vulnerability.</p>
<p>ABB investigated potentially malicious user reset activities and blocked those user access immediately to reduce the exploitation risk. The credentials of those users have been deleted after the software fix was deployed and the users were informed that they must reset their password to gain access to dynovaPRO™ again.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/4jde002044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12649</id>
    <title>bdu:2026-12649</title>
    <updated>2026-10-02T12:59:40.174575+00:00</updated>
    <content>bdu:2026-12649</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-18963</id>
    <title>BIT-keycloak-2026-18963 — Flaw in the reset-credentials flow of the keycloak-services component</title>
    <updated>2026-10-02T12:59:40.174592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: keycloak</p>
<p>A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-keycloak-2026-18963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078</id>
    <title>certfr-2026-avi-1078 — De multiples vulnérabilités ont été découvertes dans Keycloak. Elles permettent à un attaquant de provoquer un contourn…</title>
    <updated>2026-10-02T12:59:40.174619+00:00</updated>
    <content>certfr-2026-avi-1078</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364640</id>
    <title>EUVD-2026-364640</title>
    <updated>2026-10-02T12:59:40.174637+00:00</updated>
    <content>EUVD-2026-364640</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364640"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18963</id>
    <title>fkie_cve-2026-18963</title>
    <updated>2026-10-02T12:59:40.174648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-18963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4gv3-mc9p-5wqc</id>
    <title>GHSA-4gv3-mc9p-5wqc — Keycloak: Unauthenticated account takeover via reset-credentials flow bypass</title>
    <updated>2026-10-02T12:59:40.174670+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.keycloak:keycloak-services</p>
<p>A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4gv3-mc9p-5wqc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-265-06</id>
    <title>ICSA-26-265-06 — Siemens Industrial Edge Management</title>
    <updated>2026-10-02T12:59:40.174693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-265-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0326</id>
    <title>NCSC-2026-0326 — Kwetsbaarheden verholpen in Keycloak</title>
    <updated>2026-10-02T12:59:40.174712+00:00</updated>
    <content>NCSC-2026-0326</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0326"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:56519</id>
    <title>RHSA-2026:56519 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.15 Images Security Update</title>
    <updated>2026-10-02T12:59:40.174734+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:56519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-503852</id>
    <title>SSA-503852 — SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management</title>
    <updated>2026-10-02T12:59:40.174749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.</p>
<p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-503852"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2915</id>
    <title>WID-SEC-W-2026-2915 — Keycloak: Mehrere Schwachstellen</title>
    <updated>2026-10-02T12:59:40.174764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen und dadurch Benutzerkonten zu übernehmen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2915"/>
  </entry>
</feed>
