<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:23:40.746288+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-06_vde-2026-041</id>
    <title>Advisory2026-06_VDE-2026-041 — CODESYS PROFINET Controller - Out-of-bounds Write</title>
    <updated>2026-10-03T17:23:40.800684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.</p>
<p>The vulnerability in the CODESYS PROFINET Controller is caused by an out‑of‑bounds write during the processing of received invalid PROFINET communication data. Triggering this condition causes the CODESYS Control runtime system to handle the resulting exception and stop the affected PLC application in a controlled manner. Remote code execution is not considered feasible, as the execution flow remains controlled.</p>
<p>This issue affects only CODESYS projects that include a PROFINET Controller configuration.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-06_vde-2026-041"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342371</id>
    <title>EUVD-2026-342371</title>
    <updated>2026-10-03T17:23:40.800771+00:00</updated>
    <content>EUVD-2026-342371</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35226</id>
    <title>fkie_cve-2026-35226</title>
    <updated>2026-10-03T17:23:40.800796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35226"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jxhr-7f6w-54g7</id>
    <title>GHSA-jxhr-7f6w-54g7</title>
    <updated>2026-10-03T17:23:40.800844+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in a controlled stop of the PLC application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jxhr-7f6w-54g7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2555</id>
    <title>WID-SEC-W-2026-2555 — CODESYS: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T17:23:40.800875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in CODESYS ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2555"/>
  </entry>
</feed>
