<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:56:55.293876+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-01_vde-2026-012</id>
    <title>Advisory2026-01_VDE-2026-012 — CODESYS Installer - Possible Privilege Escalation</title>
    <updated>2026-10-02T14:56:55.297002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CODESYS Installer is affected by a privilege escalation vulnerability. Due to a race condition, a local attacker with limited privileges can replace the verified downloaded setup before execution. Because the update process runs with administrator privileges, a malicious application can be executed with elevated rights.
The attack requires the legitimate user to confirm the self‑update prompt for the CODESYS Installer itself or to initiate an installation of a CODESYS Development System. The update process for CODESYS Add-Ons is not affected by this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-01_vde-2026-012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275267</id>
    <title>EUVD-2026-275267</title>
    <updated>2026-10-02T14:56:55.297049+00:00</updated>
    <content>EUVD-2026-275267</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2364</id>
    <title>fkie_cve-2026-2364</title>
    <updated>2026-10-02T14:56:55.297065+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS installer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-2364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wjf9-5g6m-rgcr</id>
    <title>GHSA-wjf9-5g6m-rgcr</title>
    <updated>2026-10-02T14:56:55.297087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS installer.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wjf9-5g6m-rgcr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0640</id>
    <title>WID-SEC-W-2026-0640 — CODESYS Installer: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-02T14:56:55.297101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in CODESYS Installer ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0640"/>
  </entry>
</feed>
