<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:12:49.611350+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00477</id>
    <title>bdu:2026-00477</title>
    <updated>2026-10-02T14:12:49.619287+00:00</updated>
    <content>bdu:2026-00477</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0044</id>
    <title>certfr-2026-avi-0044 — De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaqua…</title>
    <updated>2026-10-02T14:12:49.619322+00:00</updated>
    <content>certfr-2026-avi-0044</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343001</id>
    <title>EUVD-2026-343001</title>
    <updated>2026-10-02T14:12:49.619341+00:00</updated>
    <content>EUVD-2026-343001</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21265</id>
    <title>fkie_cve-2026-21265</title>
    <updated>2026-10-02T14:12:49.619355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot.
The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees.</p>
<p>Certificate Authority (CA)
Location
Purpose
Expiration Date</p>
<p>Microsoft Corporation KEK CA 2011
KEK
Signs updates to the DB and DBX
06/24/2026</p>
<p>Microsoft Corporation UEFI CA 2011
DB
Signs 3rd party boot loaders, Option ROMs, etc.
06/27/2026</p>
<p>Microsoft Windows Production PCA 2011
DB
Signs the Windows Boot Manager
10/19/2026</p>
<p>For more information see this CVE and Windows Secure Boot certificate expiration and CA updates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-21265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xqxc-72vf-v8f5</id>
    <title>GHSA-xqxc-72vf-v8f5</title>
    <updated>2026-10-02T14:12:49.619398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot.
The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees.</p>
<p>Certificate Authority (CA)
Location
Purpose
Expiration Date</p>
<p>Microsoft Corporation KEK CA 2011
KEK
Signs updates to the DB and DBX
06/24/2026</p>
<p>Microsoft Corporation UEFI CA 2011
DB
Signs 3rd party boot loaders, Option ROMs, etc.
06/27/2026</p>
<p>Microsoft Windows Production PCA 2011
DB
Signs the Windows Boot Manager
10/19/2026</p>
<p>For more information see this CVE and Windows Secure Boot certificate expiration and CA updates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xqxc-72vf-v8f5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2026-004359</id>
    <title>jvndb-2026-004359</title>
    <updated>2026-10-02T14:12:49.619426+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CVE-2023-31096 | MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability
CVE-2024-55414 | Windows Motorola Soft Modem Driver Elevation of Privilege Vulnerability
CVE-2026-20804 | Windows Hello Tampering Vulnerability
CVE-2026-20805 | Desktop Window Manager Information Disclosure Vulnerability
CVE-2026-20809 | Windows Kernel Memory Elevation of Privilege Vulnerability
CVE-2026-20810 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-20812 | LDAP Tampering Vulnerability
CVE-2026-20814 | DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2026-20816 | Windows Installer Elevation of Privilege Vulnerability
CVE-2026-20817 | Windows Error Reporting Service Elevation of Privilege Vulnerability
CVE-2026-20820 | Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-20821 | Remote Procedure Call Information Disclosure Vulnerability
CVE-2026-20822 | Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-20823 | Windows File Explorer Information Disclosure Vulnerability
CVE-2026-20824 | Windows Remote Assistance Security Feature Bypass Vulnerability
CVE-2026-20825 | Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-20826 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
CVE-2026-20827 | Tablet Windows User Interface (TWINUI) Subsystem Information Disclosure Vulnerability
CVE-2026-208…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2026-004359"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-21265</id>
    <title>msrc_CVE-2026-21265 — Secure Boot Certificate Expiration Security Feature Bypass Vulnerability</title>
    <updated>2026-10-02T14:12:49.619470+00:00</updated>
    <content>msrc_CVE-2026-21265</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-21265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0007</id>
    <title>NCSC-2026-0007 — Kwetsbaarheden verholpen in Microsoft Windows</title>
    <updated>2026-10-02T14:12:49.619487+00:00</updated>
    <content>NCSC-2026-0007</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21265</id>
    <title>UBUNTU-CVE-2026-21265</title>
    <updated>2026-10-02T14:12:49.619559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: secureboot-db, Ubuntu:14.04:LTS: shim, Ubuntu:14.04:LTS: shim-signed, Ubuntu:16.04:LTS: secureboot-db, Ubuntu:16.04:LTS: shim, Ubuntu:16.04:LTS: shim-signed</p>
<p>Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-21265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0083</id>
    <title>WID-SEC-W-2026-0083 — Microsoft Windows : Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:12:49.619595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in verschiedenen Versionen von Microsoft Windows und Microsoft Windows Server ausnutzen,, um erweiterte Privilegien, einschließlich Benutzer- und Administratorrechten, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen und Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0083"/>
  </entry>
</feed>
