<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:19:38.430017+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351151</id>
    <title>EUVD-2026-351151</title>
    <updated>2026-10-04T09:19:38.485160+00:00</updated>
    <content>EUVD-2026-351151</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-56022</id>
    <title>fkie_cve-2026-56022</title>
    <updated>2026-10-04T09:19:38.485199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-56022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9848-6qgw-2748</id>
    <title>GHSA-9848-6qgw-2748</title>
    <updated>2026-10-04T09:19:38.485232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9848-6qgw-2748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/va-26-169-02</id>
    <title>VA-26-169-02 — Webmin multiple vulnerabilities</title>
    <updated>2026-10-04T09:19:38.485249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.202. Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern. Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/va-26-169-02"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2014</id>
    <title>WID-SEC-W-2026-2014 — Webmin: Mehrere Schwachstellen</title>
    <updated>2026-10-04T09:19:38.485274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Webmin ausnutzen, um falsche Informationen darzustellen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2014"/>
  </entry>
</feed>
