<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:07:15.718629+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-340541</id>
    <title>EUVD-2026-340541</title>
    <updated>2026-10-02T11:07:15.768209+00:00</updated>
    <content>EUVD-2026-340541</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-340541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34496</id>
    <title>fkie_cve-2026-34496</title>
    <updated>2026-10-02T11:07:15.768254+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.</p>
<p>This issue affects victor Web: before 7.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f4xv-vq6q-4wwv</id>
    <title>GHSA-f4xv-vq6q-4wwv</title>
    <updated>2026-10-02T11:07:15.768287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233.</p>
<p>This issue affects victor Web: before 7.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f4xv-vq6q-4wwv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-204-01</id>
    <title>ICSA-26-204-01 — Johnson Controls C-CURE 9000 and Victor application server (Update A)</title>
    <updated>2026-10-02T11:07:15.768304+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls. Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-204-01"/>
  </entry>
</feed>
