<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:29:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-340540</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-340540</link>
      <description>EUVD-2026-340540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-340540</guid>
    </item>
    <item>
      <title>fkie_cve-2026-21653</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-21653</link>
      <description>&lt;p&gt;Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.&lt;/p&gt;
&lt;p&gt;This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.&lt;/p&gt;
&lt;p&gt;This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-21653</guid>
    </item>
    <item>
      <title>GHSA-v48g-g9wj-ffhr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v48g-g9wj-ffhr</link>
      <description>&lt;p&gt;Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.&lt;/p&gt;
&lt;p&gt;This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery.&lt;/p&gt;
&lt;p&gt;This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v48g-g9wj-ffhr</guid>
    </item>
    <item>
      <title>ICSA-26-204-01 — Johnson Controls C-CURE 9000 and Victor application server (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-204-01</link>
      <description>&lt;p&gt;Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls. Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on an adjacent network to achieve arbitrary code execution on the C-CURE 9000, victor application server and victor, as well as connected clients (e.g., workstations of physical security personnel). Such attack could impact physical security controls. Under certain circumstances, successful exploitation of this vulnerability could allow an attacker to forge server-side HTTP requests from the victor Web application. This could be leveraged to interact with internal services running on the host or accessible on the local network, potentially leading to unauthorized information disclosure or lateral movement within the network. Under certain circumstances, successful exploitation of this vulnerability could result in low privilege users accessing unauthorized pages such as Users and Logs. Successful exploitation could allow an attacker to view sensitive system information, user account details, and audit logs beyond their intended access level, potentially enabling further attacks or unauthorized administrative actions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-204-01</guid>
    </item>
  </channel>
</rss>
