<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:39:24.809949+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1134</id>
    <title>certfr-2026-avi-1134 — De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T21:39:24.832697+00:00</updated>
    <content>certfr-2026-avi-1134</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364881</id>
    <title>EUVD-2026-364881</title>
    <updated>2026-10-02T21:39:24.832745+00:00</updated>
    <content>EUVD-2026-364881</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364881"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-76969</id>
    <title>fkie_cve-2026-76969</title>
    <updated>2026-10-02T21:39:24.832762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-76969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-955m-rr6m-2f9v</id>
    <title>GHSA-955m-rr6m-2f9v — @sap/cds-mtx: Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)</title>
    <updated>2026-10-02T21:39:24.832796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @sap/cds-mtxs</p>
<p>@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-955m-rr6m-2f9v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0356</id>
    <title>NCSC-2026-0356 — Kwetsbaarheden verholpen in diverse SAP-producten</title>
    <updated>2026-10-02T21:39:24.832825+00:00</updated>
    <content>NCSC-2026-0356</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0356"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3220</id>
    <title>WID-SEC-W-2026-3220 — SAP Patch Day September 2026: Mehrere Schwachstellen</title>
    <updated>2026-10-02T21:39:24.832858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in SAP Software ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Berechtigungen zu erweitern, vertrauliche Informationen offenzulegen oder zu manipulieren, SQL-Injection-Angriffe durchzuführen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3220"/>
  </entry>
</feed>
