<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:49:38.626865+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:41893</id>
    <title>ALSA-2026:41893 — Important: .NET 8.0 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:49:38.777697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: aspnetcore-runtime-8.0, AlmaLinux:10: aspnetcore-runtime-dbg-8.0, AlmaLinux:10: aspnetcore-targeting-pack-8.0, AlmaLinux:10: dotnet-apphost-pack-8.0, AlmaLinux:10: dotnet-hostfxr-8.0, AlmaLinux:10: dotnet-runtime-8.0, AlmaLinux:10: dotnet-runtime-dbg-8.0, AlmaLinux:10: dotnet-sdk-8.0, AlmaLinux:10: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:10: dotnet-sdk-dbg-8.0 and 2 more</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.</p>
<p>Security Fix(es):</p>
<p>* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
  * dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
  * ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
  * ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
  * ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
  * dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
  * dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
  * dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
  * dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
  * dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
  * dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
  * dotnet: .NET: Denial of Service due to uncontrolled re…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:41893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09808</id>
    <title>bdu:2026-09808</title>
    <updated>2026-10-03T17:49:38.777810+00:00</updated>
    <content>bdu:2026-09808</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-dotnet-2026-50649</id>
    <title>BIT-dotnet-2026-50649 — .NET Remote Code Execution Vulnerability</title>
    <updated>2026-10-03T17:49:38.777829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: dotnet</p>
<p>Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-dotnet-2026-50649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0869</id>
    <title>certfr-2026-avi-0869 — De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaqua…</title>
    <updated>2026-10-03T17:49:38.777851+00:00</updated>
    <content>certfr-2026-avi-0869</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0869"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-376855</id>
    <title>EUVD-2026-376855</title>
    <updated>2026-10-03T17:49:38.777868+00:00</updated>
    <content>EUVD-2026-376855</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-376855"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50649</id>
    <title>fkie_cve-2026-50649</title>
    <updated>2026-10-03T17:49:38.777880+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50649</id>
    <title>msrc_CVE-2026-50649 — .NET Remote Code Execution Vulnerability</title>
    <updated>2026-10-03T17:49:38.777900+00:00</updated>
    <content>msrc_CVE-2026-50649</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-50649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0235</id>
    <title>NCSC-2026-0235 — Kwetsbaarheden verholpen in Microsoft Developer Tools</title>
    <updated>2026-10-03T17:49:38.777917+00:00</updated>
    <content>NCSC-2026-0235</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0235"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:27171</id>
    <title>RHSA-2026:27171 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T17:49:38.777957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local code execution via deserialization of untrusted data dotnet: .NET Framework: Privilege escalation via code injection dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM dotnet: .NET Core: Denial of Service via type confusion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:27171"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:41893</id>
    <title>RHSA-2026:41893 — Red Hat Security Advisory: .NET 8.0 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:49:38.777995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Security Feature Bypass Vulnerability dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local code execution via deserialization of untrusted data dotnet: .NET Framework: Privilege escalation via code injection dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:41893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:41893</id>
    <title>RLSA-2026:41893 — Important: .NET 8.0 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T17:49:38.778044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: dotnet8.0</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.</p>
<p>Security Fix(es):</p>
<p>* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)</p>
<p>* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)</p>
<p>* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)</p>
<p>* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)</p>
<p>* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)</p>
<p>* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)</p>
<p>* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)</p>
<p>* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)</p>
<p>* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)</p>
<p>* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)</p>
<p>* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)</p>
<p>* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)</p>
<p>* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (C…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:41893"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50649</id>
    <title>UBUNTU-CVE-2026-50649</title>
    <updated>2026-10-03T17:49:38.778088+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dotnet7</p>
<p>Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50649"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2324</id>
    <title>WID-SEC-W-2026-2324 — Microsoft DeveloperTools: Mehrere Schwachstellen</title>
    <updated>2026-10-03T17:49:38.778106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio Code, .NET Framework, Microsoft .NET, Visual Studio 2022 und Visual Studio 2026 ausnutzen, um erweiterte Berechtigungen, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen, einen Denial-of-Service-Zustand auszulösen oder Spoofing-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2324"/>
  </entry>
</feed>
