<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T23:53:24.111045+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-32666</id>
    <title>CVE-2026-32666 — Automated Logic WebCTRL Premium Server Authentication Bypass by Spoofing</title>
    <updated>2026-10-07T23:53:24.113234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Automated Logic WebCTRL Premium Server</p>
<p>WebCTRL systems that communicate over BACnet inherit the protocol's lack
 of network layer authentication. WebCTRL does not implement additional 
validation of BACnet traffic so an attacker with network access could 
spoof BACnet packets directed at either the WebCTRL server or associated
 AutomatedLogic controllers. Spoofed packets may be processed as 
legitimate.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-32666"/>
  </entry>
</feed>
