<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:11:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-321770</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-321770</link>
      <description>EUVD-2026-321770</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-321770</guid>
    </item>
    <item>
      <title>fkie_cve-2025-41669</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-41669</link>
      <description>&lt;p&gt;The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-41669</guid>
    </item>
    <item>
      <title>GHSA-m3wg-2ch3-59m2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m3wg-2ch3-59m2</link>
      <description>&lt;p&gt;The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potentially impacting integrity and availability of the PLCnext Control.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m3wg-2ch3-59m2</guid>
    </item>
    <item>
      <title>VDE-2026-050 — Phoenix Contact: PLCnext Firmware Security Issues Related to APPs and Configuration Files</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2026-050</link>
      <description>&lt;p&gt;This advisory addresses security issues in PLCnext firmware versions prior to 2026.0.3 that are related to APP handling and the processing of configuration files. The identified vulnerabilities affect APP installation authenticity as well as the handling of configuration data in writable directories. Successful exploitation may allow authenticated attackers with different privilege levels to compromise integrity, availability, and system security of affected PLCnext Control. Both issues are resolved starting with PLCnext firmware version 2026.0.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This advisory addresses security issues in PLCnext firmware versions prior to 2026.0.3 that are related to APP handling and the processing of configuration files. The identified vulnerabilities affect APP installation authenticity as well as the handling of configuration data in writable directories. Successful exploitation may allow authenticated attackers with different privilege levels to compromise integrity, availability, and system security of affected PLCnext Control. Both issues are resolved starting with PLCnext firmware version 2026.0.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2026-050</guid>
    </item>
  </channel>
</rss>
