<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:04:35.264428+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga003144</id>
    <title>2NGA003144 — ABB AbilityTM zenon Security Risk Due to High-Severity Vulnerabilities in WIBU CodeMeter Runtime</title>
    <updated>2026-10-02T10:04:35.311201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of publicly disclosed security vulnerabilities affecting the WIBU-Systems CodeMeter Runtime for Windows, identified as CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576. The CodeMeter Runtime component is used within affected ABB zenon Software Platform installations for software licensing and license server functionality. Successful exploitation of the reported vulnerabilities could enable local privilege escalation on Windows systems and impact systems configured as CodeMeter license servers, potentially leading to unauthorized access, service disruption, or loss of system integrity. Refer to the WIBU-Systems advisory for detailed technical information on each vulnerability. Please see the References section for the WIBU-Systems security advisory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga003144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-359884</id>
    <title>EUVD-2026-359884</title>
    <updated>2026-10-02T10:04:35.311279+00:00</updated>
    <content>EUVD-2026-359884</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-359884"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-81576</id>
    <title>fkie_cve-2026-81576</title>
    <updated>2026-10-02T10:04:35.311296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read
license information belonging to another handle.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-81576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gj9j-5pfx-gc7p</id>
    <title>GHSA-gj9j-5pfx-gc7p</title>
    <updated>2026-10-02T10:04:35.311320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak
SID as sole authenticator. An attacker can brute-force the SID, recover another session's handle number, and read
license information belonging to another handle.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gj9j-5pfx-gc7p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0333</id>
    <title>NCSC-2026-0333 — Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems</title>
    <updated>2026-10-02T10:04:35.311336+00:00</updated>
    <content>NCSC-2026-0333</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2026-0011</id>
    <title>sca-2026-0011 — Vulnerabilities in Wibu Systems CodeMeter Runtime Affect Multiple SICK Products</title>
    <updated>2026-10-02T10:04:35.311354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such as junctions or symbolic links, before file operations are performed. A local attacker can create a junction at the temporary file that points to an arbitrary system path. Because CodeMeter Runtime runs with System privileges, this could allow arbitrary files to be deleted with System privileges and potentially enable local privilege escalation. If CodeMeter Runtime is configured as a server, the configuration command handler does not enforce network-origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. The logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format specifiers. This can be used to reliably crash CodeMeter and disclose sensitive information such as process memory and stack canaries. The attack works locally, for example by using cmu --set-proxy to set the proxy value, and remotely when combined with CVE‑2026‑81573 by setting General.ProxyServer and then triggering this vulnerability. If configured as a server, CodeMeter Runtime accepts requests with opcode 0x5e, wh…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2026-0011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-091</id>
    <title>VDE-2026-091 — TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities</title>
    <updated>2026-10-02T10:04:35.311389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-091"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3004</id>
    <title>WID-SEC-W-2026-3004 — Wibu-Systems CodeMeter Runtime: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:04:35.311407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Wibu-Systems CodeMeter Runtime ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Berechtigungen zu erweitern und Administratorrechte zu erlangen oder Denial-of-Service-Zustände herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3004"/>
  </entry>
</feed>
