<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:13:22 +0000</lastBuildDate>
    <item>
      <title>4JDE002044 — dynovaPRO™ Reset Credentials Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/4jde002044</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerability in the product listed as affected in the advisory. An update has been deployed to the cloud system that resolves a publicly reported vulnerability in the product versions listed above.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability could take remote control of the product.&lt;/p&gt;
&lt;p&gt;The vulnerability has been identified in the keycloak authentication component which is integrated into dynovaPRO™. The vulnerability exists in the &amp;#39;Forgot Password&amp;#39; functionality and allows unauthenticated attackers to bypass authentication and hijack user accounts.&lt;/p&gt;
&lt;p&gt;Users who have received a password reset mail before the mentioned date, without having requested it, are thereby potentially attacked by exploiting this vulnerability.&lt;/p&gt;
&lt;p&gt;ABB investigated potentially malicious user reset activities and blocked those user access immediately to reduce the exploitation risk. The credentials of those users have been deleted after the software fix was deployed and the users were informed that they must reset their password to gain access to dynovaPRO™ again.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerability in the product listed as affected in the advisory. An update has been deployed to the cloud system that resolves a publicly reported vulnerability in the product versions listed above.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability could take remote control of the product.&lt;/p&gt;
&lt;p&gt;The vulnerability has been identified in the keycloak authentication component which is integrated into dynovaPRO™. The vulnerability exists in the &amp;#39;Forgot Password&amp;#39; functionality and allows unauthenticated attackers to bypass authentication and hijack user accounts.&lt;/p&gt;
&lt;p&gt;Users who have received a password reset mail before the mentioned date, without having requested it, are thereby potentially attacked by exploiting this vulnerability.&lt;/p&gt;
&lt;p&gt;ABB investigated potentially malicious user reset activities and blocked those user access immediately to reduce the exploitation risk. The credentials of those users have been deleted after the software fix was deployed and the users were informed that they must reset their password to gain access to dynovaPRO™ again.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/4jde002044</guid>
    </item>
    <item>
      <title>bdu:2026-12649</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12649</link>
      <description>bdu:2026-12649</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12649</guid>
    </item>
    <item>
      <title>BIT-keycloak-2026-18963 — Flaw in the reset-credentials flow of the keycloak-services component</title>
      <link>https://cve.radiocsirt.org/vuln/bit-keycloak-2026-18963</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: keycloak&lt;/p&gt;
&lt;p&gt;A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-keycloak-2026-18963</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1078 — De multiples vulnérabilités ont été découvertes dans Keycloak. Elles permettent à un attaquant de provoquer un contourn…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078</link>
      <description>certfr-2026-avi-1078</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1078</guid>
    </item>
    <item>
      <title>EUVD-2026-364640</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-364640</link>
      <description>EUVD-2026-364640</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-364640</guid>
    </item>
    <item>
      <title>fkie_cve-2026-18963</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18963</link>
      <description>&lt;p&gt;A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-18963</guid>
    </item>
    <item>
      <title>GHSA-4gv3-mc9p-5wqc — Keycloak: Unauthenticated account takeover via reset-credentials flow bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4gv3-mc9p-5wqc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-services&lt;/p&gt;
&lt;p&gt;A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4gv3-mc9p-5wqc</guid>
    </item>
    <item>
      <title>ICSA-26-265-06 — Siemens Industrial Edge Management</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-265-06</link>
      <description>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-265-06</guid>
    </item>
    <item>
      <title>NCSC-2026-0326 — Kwetsbaarheden verholpen in Keycloak</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0326</link>
      <description>NCSC-2026-0326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0326</guid>
    </item>
    <item>
      <title>RHSA-2026:56519 — Red Hat Security Advisory: Red Hat build of Keycloak 26.4.15 Images Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:56519</link>
      <description>&lt;p&gt;keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:56519</guid>
    </item>
    <item>
      <title>SSA-503852 — SSA-503852: Authentication Bypass Vulnerability in Industrial Edge Management</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-503852</link>
      <description>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification.&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for the affected products and recommends to update to the latest versions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-503852</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2915 — Keycloak: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2915</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen und dadurch Benutzerkonten zu übernehmen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Keycloak ausnutzen, um Sicherheitsvorkehrungen zu umgehen und dadurch Benutzerkonten zu übernehmen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2915</guid>
    </item>
  </channel>
</rss>
