<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T01:43:12.249318+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329852</id>
    <title>EUVD-2026-329852</title>
    <updated>2026-10-05T01:43:12.252052+00:00</updated>
    <content>EUVD-2026-329852</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329852"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57301</id>
    <title>fkie_cve-2026-57301</title>
    <updated>2026-10-05T01:43:12.252083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57301"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5qh3-hxx9-w26p</id>
    <title>GHSA-5qh3-hxx9-w26p — Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE</title>
    <updated>2026-10-05T01:43:12.252112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.jenkins-ci.plugins:zapper</p>
<p>Jenkins OWASP ZAP Plugin 1.0.7 and earlier does not support distributed builds, causing the file operations and build process of its "Automatically build ZAP" feature to be performed on the Jenkins controller rather than on the agent the build is assigned to.</p>
<p>This allows attackers with Item/Configure permission to configure the feature to build an attacker-controlled project, executing arbitrary code on the Jenkins controller and bypassing any restriction confining the build to a specific agent.</p>
<p>As of publication of this advisory, there is no fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5qh3-hxx9-w26p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074</id>
    <title>WID-SEC-W-2026-2074 — Jenkins Plugins: Mehrere Schwachstellen</title>
    <updated>2026-10-05T01:43:12.252141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2074"/>
  </entry>
</feed>
