<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:10:31.884067+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:58555</id>
    <title>ALSA-2026:58555 — Moderate: NetworkManager security update</title>
    <updated>2026-10-02T11:10:31.918355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: NetworkManager, AlmaLinux:8: NetworkManager-adsl, AlmaLinux:8: NetworkManager-bluetooth, AlmaLinux:8: NetworkManager-cloud-setup, AlmaLinux:8: NetworkManager-config-connectivity-redhat, AlmaLinux:8: NetworkManager-config-server, AlmaLinux:8: NetworkManager-dispatcher-routing-rules, AlmaLinux:8: NetworkManager-initscripts-updown, AlmaLinux:8: NetworkManager-libnm, AlmaLinux:8: NetworkManager-libnm-devel and 6 more</p>
<p>NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.</p>
<p>Security Fix(es):</p>
<p>* NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:58555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-375530</id>
    <title>EUVD-2026-375530</title>
    <updated>2026-10-02T11:10:31.918447+00:00</updated>
    <content>EUVD-2026-375530</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-375530"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10805</id>
    <title>fkie_cve-2026-10805</title>
    <updated>2026-10-02T11:10:31.918464+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-10805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rwc7-7qq8-w477</id>
    <title>GHSA-rwc7-7qq8-w477</title>
    <updated>2026-10-02T11:10:31.918489+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rwc7-7qq8-w477"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2822</id>
    <title>OESA-2026-2822 — NetworkManager security update</title>
    <updated>2026-10-02T11:10:31.918505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: NetworkManager</p>
<p>NetworkManager attempts to keep an active network connection available at all times.  The point of NetworkManager is to make networking configuration and setup as painless and automatic as possible. If using DHCP, NetworkManager is intended to replace default routes, obtain IP addresses from a DHCP server, and change name servers whenever it sees fit.

Security Fix(es):</p>
<p>A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;apos;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.(CVE-2026-10805)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2822"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11693-1</id>
    <title>openSUSE-SU-2026:11693-1 — NetworkManager-1.56.1-4.1 on GA media</title>
    <updated>2026-10-02T11:10:31.918531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NetworkManager-1.56.1-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11693-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:61239</id>
    <title>RHSA-2026:61239 — Red Hat Security Advisory: NetworkManager security update</title>
    <updated>2026-10-02T11:10:31.918549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:61239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:58555</id>
    <title>RLSA-2026:58555 — Moderate: NetworkManager security update</title>
    <updated>2026-10-02T11:10:31.918565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: NetworkManager</p>
<p>NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.</p>
<p>Security Fix(es):</p>
<p>* NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:58555"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23475-1</id>
    <title>SUSE-SU-2026:23475-1 — Security update for NetworkManager</title>
    <updated>2026-10-02T11:10:31.918587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for NetworkManager</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23475-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10805</id>
    <title>UBUNTU-CVE-2026-10805</title>
    <updated>2026-10-02T11:10:31.918602+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: network-manager, Ubuntu:18.04:LTS: network-manager, Ubuntu:20.04:LTS: network-manager, Ubuntu:22.04:LTS: network-manager, Ubuntu:24.04:LTS: network-manager, Ubuntu:25.10: network-manager, Ubuntu:26.04:LTS: network-manager</p>
<p>A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2977</id>
    <title>WID-SEC-W-2026-2977 — Red Hat Enterprise Linux (NetworkManager): Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-02T11:10:31.918629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (NetworkManager) ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2977"/>
  </entry>
</feed>
