<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:57:45.835276+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-340540</id>
    <title>EUVD-2026-340540</title>
    <updated>2026-10-03T10:57:45.885168+00:00</updated>
    <content>EUVD-2026-340540</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-340540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21653</id>
    <title>fkie_cve-2026-21653</title>
    <updated>2026-10-03T10:57:45.885206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.</p>
<p>This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-21653"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v48g-g9wj-ffhr</id>
    <title>GHSA-v48g-g9wj-ffhr</title>
    <updated>2026-10-03T10:57:45.885240+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.</p>
<p>This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v48g-g9wj-ffhr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-204-01</id>
    <title>ICSA-26-204-01 — Johnson Controls C-CURE 9000 and Victor application server (Update A)</title>
    <updated>2026-10-03T10:57:45.885256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls. Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-204-01"/>
  </entry>
</feed>
