<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:53:38.477453+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/advisory2026-09_vde-2026-055</id>
    <title>Advisory2026-09_VDE-2026-055 — CODESYS Development System - Incorrect Default Permissions</title>
    <updated>2026-10-02T11:53:38.512074+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Two local privilege escalation vulnerabilities were identified in the CODESYS Development System. Specifically, the PackageManager and the IPM create temporary directories with insecure default permissions when executed with administrative privileges. This allows low-privileged local users to modify a temporary bootstrap file to force the deployment of arbitrary components, or to exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition to replace digitally verified installation files with malicious ones prior to installation. Both flaws bypass intended security boundaries during the installation of packages or add-ons.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/advisory2026-09_vde-2026-055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321196</id>
    <title>EUVD-2026-321196</title>
    <updated>2026-10-02T11:53:38.512122+00:00</updated>
    <content>EUVD-2026-321196</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321196"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44468</id>
    <title>fkie_cve-2026-44468</title>
    <updated>2026-10-02T11:53:38.512137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44468"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x347-p9xc-q762</id>
    <title>GHSA-x347-p9xc-q762</title>
    <updated>2026-10-02T11:53:38.512161+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x347-p9xc-q762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1675</id>
    <title>WID-SEC-W-2026-1675 — CODESYS: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:53:38.512176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in CODESYS ausnutzen, um seine Privilegien zu erhöhen, um Daten zu manipulieren, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1675"/>
  </entry>
</feed>
