<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:13:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-264205</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264205</link>
      <description>EUVD-2026-264205</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264205</guid>
    </item>
    <item>
      <title>fkie_cve-2025-11538</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-11538</link>
      <description>&lt;p&gt;A vulnerability exists in Keycloak&amp;#39;s server distribution where enabling debug mode (--debug &amp;lt;port&amp;gt;) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists in Keycloak&amp;#39;s server distribution where enabling debug mode (--debug &amp;lt;port&amp;gt;) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-11538</guid>
    </item>
    <item>
      <title>GHSA-j4vq-q93m-4683 — Keycloak has debug default bind address</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j4vq-q93m-4683</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-quarkus-dist&lt;/p&gt;
&lt;p&gt;A vulnerability exists in Keycloak&amp;#39;s server distribution where enabling debug mode (`--debug`) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (`0.0.0.0`). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.&lt;/p&gt;
&lt;p&gt;Red Hat evaluates this as a Moderate impact vulnerability due to the requirement of running debug mode and untrusted network. Also, for Red Hat Single Sign-On, this must as well be bound to 0.0.0.0 address, which is not recommended in production scenarios.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-quarkus-dist&lt;/p&gt;
&lt;p&gt;A vulnerability exists in Keycloak&amp;#39;s server distribution where enabling debug mode (`--debug`) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (`0.0.0.0`). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.&lt;/p&gt;
&lt;p&gt;Red Hat evaluates this as a Moderate impact vulnerability due to the requirement of running debug mode and untrusted network. Also, for Red Hat Single Sign-On, this must as well be bound to 0.0.0.0 address, which is not recommended in production scenarios.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j4vq-q93m-4683</guid>
    </item>
    <item>
      <title>jvndb-2026-026852</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-026852</link>
      <description>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-2026-3911, CVE-2026-4282, CVE-2026-4325, CVE-2026-4634, CVE-2026-22745, CVE-2026-22748, CVE-2026-25854, CVE-2026-40972, CVE-2026-40975&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities exist in Hitachi Ops Center Common Services.&#13;
&#13;
CVE-2025-10939, CVE-2025-11537, CVE-2025-11538, CVE-2025-12110, CVE-2025-13467, CVE-2025-13881, CVE-2025-14082, CVE-2025-14083, CVE-2025-14777, CVE-2025-66560, CVE-2026-0707, CVE-2026-0871, CVE-2026-0976, CVE-2026-1035, CVE-2026-1190, CVE-2026-2092, CVE-2026-2575, CVE-2026-2673, CVE-2026-3009, CVE-2026-3121, CVE-2026-3429, CVE-2026-3872, CVE-2026-3911, CVE-2026-4282, CVE-2026-4325, CVE-2026-4634, CVE-2026-22745, CVE-2026-22748, CVE-2026-25854, CVE-2026-40972, CVE-2026-40975&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-026852</guid>
    </item>
    <item>
      <title>RHSA-2025:21370 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.4 Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:21370</link>
      <description>&lt;p&gt;org.keycloak/keycloak-quarkus-server: Unable to restrict access to the admin console keycloak-server: Debug default bind address keycloak: org.keycloak:keycloak-services: User can refresh offline session even after client&amp;#39;s offline_access scope was removed org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass org.keycloak.protocol.oidc.endpoints.LogoutEndpoint: Offline Session takeover due to reused Authentication Session ID&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;org.keycloak/keycloak-quarkus-server: Unable to restrict access to the admin console keycloak-server: Debug default bind address keycloak: org.keycloak:keycloak-services: User can refresh offline session even after client&amp;#39;s offline_access scope was removed org.keycloak/keycloak-services: WebAuthn Attestation Statement Verification Bypass org.keycloak.protocol.oidc.endpoints.LogoutEndpoint: Offline Session takeover due to reused Authentication Session ID&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:21370</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2606 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2606</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um beliebigen Programmcode auszuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um beliebigen Programmcode auszuführen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2606</guid>
    </item>
  </channel>
</rss>
