<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:08:22 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</link>
      <description>certfr-2026-avi-0199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AJ02810 — Security fixes in kserve-modelmesh 0.12.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-aj02810</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kserve-modelmesh&lt;/p&gt;
&lt;p&gt;Package kserve-modelmesh version 0.12.0-r0 fixes 20 vulnerabilities: CVE-2026-24281, CVE-2026-24308, CVE-2026-33870, CVE-2026-33871, ghsa-7xrh-hqfc-g7qr...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kserve-modelmesh&lt;/p&gt;
&lt;p&gt;Package kserve-modelmesh version 0.12.0-r0 fixes 20 vulnerabilities: CVE-2026-24281, CVE-2026-24308, CVE-2026-33870, CVE-2026-33871, ghsa-7xrh-hqfc-g7qr...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-aj02810</guid>
    </item>
    <item>
      <title>EUVD-2026-266294</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266294</link>
      <description>EUVD-2026-266294</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266294</guid>
    </item>
    <item>
      <title>fkie_cve-2026-1225</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1225</link>
      <description>&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.&lt;/p&gt;
&lt;p&gt;The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must  have write access to a 
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.&lt;/p&gt;
&lt;p&gt;The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must  have write access to a 
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-1225</guid>
    </item>
    <item>
      <title>GHSA-qqpg-mvqg-649v — Logback allows an attacker to instantiate classes already present on the class path</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qqpg-mvqg-649v</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.&lt;/p&gt;
&lt;p&gt;The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must  have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: ch.qos.logback:logback-core&lt;/p&gt;
&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.&lt;/p&gt;
&lt;p&gt;The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must  have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qqpg-mvqg-649v</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10114-1 — logback-1.2.13-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10114-1</link>
      <description>&lt;p&gt;logback-1.2.13-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;logback-1.2.13-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10114-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0361-1 — Security update for logback</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0361-1</link>
      <description>&lt;p&gt;Security update for logback&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for logback&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0361-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-1225</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:Pro:22.04:LTS: logback, Ubuntu:24.04:LTS: logback, Ubuntu:25.10: logback, Ubuntu:26.04:LTS: logback&lt;/p&gt;
&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: logback, Ubuntu:Pro:18.04:LTS: logback, Ubuntu:Pro:20.04:LTS: logback, Ubuntu:Pro:22.04:LTS: logback, Ubuntu:24.04:LTS: logback, Ubuntu:25.10: logback, Ubuntu:26.04:LTS: logback&lt;/p&gt;
&lt;p&gt;ACE vulnerability in configuration file processing  by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The instantiation of a potentially malicious Java class requires that said class is present on the user&amp;#39;s class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1225</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0202 — Logback: Schwachstelle ermöglicht Manipulation von Daten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0202</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Logback ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Logback ausnutzen, um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0202</guid>
    </item>
  </channel>
</rss>
