<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:00:12.944639+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266638</id>
    <title>EUVD-2026-266638</title>
    <updated>2026-10-02T11:00:13.001354+00:00</updated>
    <content>EUVD-2026-266638</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266638"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41728</id>
    <title>fkie_cve-2025-41728</title>
    <updated>2026-10-02T11:00:13.001396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-41728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3gh2-3c3q-2933</id>
    <title>GHSA-3gh2-3c3q-2933</title>
    <updated>2026-10-02T11:00:13.001442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3gh2-3c3q-2933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-092</id>
    <title>VDE-2025-092 — Beckhoff: Privilege escalation and information leak via Beckhoff Device Manager</title>
    <updated>2026-10-02T11:00:13.001472+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The vulnerability CVE-2025-41726 (NN-2025-0074) allows an authenticated remote user to execute arbitrary commands on the device. This can be exploited over the web UI or via API. In one case the execution of the arbitrary command happens within a privileged process.</p>
<p>The vulnerability CVE-2025-41727 (NN-2025-0075) allows a local user with low privileges on the device to bypass the authentication mechanism of the UI and send commands to a privileged process which it executes on behalf of that user but with higher privileges. This way the local user can escalate privileges.</p>
<p>The vulnerability CVE-2025-41728 (NN-2025-0076) allows an authenticated remote user to cause an out-of-bounds read operation within a specific service process which runs on the device. The read operation might copy sensitive information from the memory of the specific service into a response message which is then provided to the user but the user cannot choose which information is disclosed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-092"/>
  </entry>
</feed>
