<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:26:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06322</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06322</link>
      <description>bdu:2026-06322</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06322</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0537 — Une vulnérabilité a été découverte dans Palo Alto Networks User-ID Authentication Portal. Elle permet à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0537</link>
      <description>certfr-2026-avi-0537</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0537</guid>
    </item>
    <item>
      <title>EUVD-2026-336363</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336363</link>
      <description>EUVD-2026-336363</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336363</guid>
    </item>
    <item>
      <title>fkie_cve-2026-0300</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0300</link>
      <description>&lt;p&gt;A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.&lt;/p&gt;
&lt;p&gt;The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.&lt;/p&gt;
&lt;p&gt;Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.&lt;/p&gt;
&lt;p&gt;The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.&lt;/p&gt;
&lt;p&gt;Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-0300</guid>
    </item>
    <item>
      <title>GHSA-3vfh-3cpw-2378</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3vfh-3cpw-2378</link>
      <description>&lt;p&gt;A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.&lt;/p&gt;
&lt;p&gt;The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.&lt;/p&gt;
&lt;p&gt;Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.&lt;/p&gt;
&lt;p&gt;The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the  best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail  by restricting access to only trusted internal IP addresses.&lt;/p&gt;
&lt;p&gt;Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3vfh-3cpw-2378</guid>
    </item>
    <item>
      <title>ICSA-26-139-02 — Siemens RUGGEDCOM APE1808 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-139-02</link>
      <description>&lt;p&gt;A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to a dataplane interface A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially ex…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface. Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition Multiple command injection vulnerabilities in Palo Alto Networks PAN-OS® software enable an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI or Web UI Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition by sending specially crafted network traffic to a dataplane interface A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially ex…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-139-02</guid>
    </item>
    <item>
      <title>NCSC-2026-0132 — Kwetsbaarheid verholpen in Palo Alto Networks PAN-OS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0132</link>
      <description>NCSC-2026-0132</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0132</guid>
    </item>
    <item>
      <title>SSA-967325 — SSA-967325: Multiple Vulnerabilities in Palo Alto Networks PAN-OS on RUGGEDCOM APE1808 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-967325</link>
      <description>&lt;p&gt;Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks&amp;#39; upstream security notifications.&lt;/p&gt;
&lt;p&gt;[1] https://security.paloaltonetworks.com/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version. Customers are advised to consult and implement the workarounds provided in Palo Alto Networks&amp;#39; upstream security notifications.&lt;/p&gt;
&lt;p&gt;[1] https://security.paloaltonetworks.com/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-967325</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1366 — Palo Alto Networks PAN-OS: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1366</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Palo Alto Networks PAN-OS ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Palo Alto Networks PAN-OS ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1366</guid>
    </item>
  </channel>
</rss>
