<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:25:13 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-352909</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-352909</link>
      <description>EUVD-2026-352909</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-352909</guid>
    </item>
    <item>
      <title>fkie_cve-2026-64887</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-64887</link>
      <description>&lt;p&gt;Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.&lt;/p&gt;
&lt;p&gt;This issue affects Airwall: before 4.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.&lt;/p&gt;
&lt;p&gt;This issue affects Airwall: before 4.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-64887</guid>
    </item>
    <item>
      <title>GHSA-4384-f96g-8272</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4384-f96g-8272</link>
      <description>&lt;p&gt;Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.&lt;/p&gt;
&lt;p&gt;This issue affects Airwall: before 4.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.&lt;/p&gt;
&lt;p&gt;This issue affects Airwall: before 4.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4384-f96g-8272</guid>
    </item>
    <item>
      <title>ICSA-26-225-03 — Johnson Controls Inc. Airwall</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-225-03</link>
      <description>&lt;p&gt;A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authentication failure that can be difficult for system or application administrators to detect. Once discovered, it is difficult to remediate without manually modifying or patching the software. The hardcoded key is identical across all installations of the product and across all customer organizations, meaning a single disclosure of the key - common on the internet - grants any knowledgeable attacker access to all affected deployments. An attacker with access to application code or binary files can use the hardcoded key to decrypt sensitive application data stored in configuration and database files, enabling further data disclosure or compromise of application infrastructure. An arbitrary file read vulnerability was identified in the Airwall application. This issue occurs when user-supplied input is directly incorporated into filesystem access functions without adequate validation or sanitization. As a result, an attacker can request and obtain the contents of arbitrary files on the server, including sensitive configuration files, source code, credential stores, and private keys, provided the application process has permission to read them. The vulnerability is commonly exploited through path traversal sequences (e.g., ../) or absolute file paths (e.g., /etc/passwd). Encoding variations of traversal sequences (e.g., %2e%2e%2f) can also bypass…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A hardcoded password or cryptographic key was identified in the Airwall application. A hardcoded credential leads to a significant authentication failure that can be difficult for system or application administrators to detect. Once discovered, it is difficult to remediate without manually modifying or patching the software. The hardcoded key is identical across all installations of the product and across all customer organizations, meaning a single disclosure of the key - common on the internet - grants any knowledgeable attacker access to all affected deployments. An attacker with access to application code or binary files can use the hardcoded key to decrypt sensitive application data stored in configuration and database files, enabling further data disclosure or compromise of application infrastructure. An arbitrary file read vulnerability was identified in the Airwall application. This issue occurs when user-supplied input is directly incorporated into filesystem access functions without adequate validation or sanitization. As a result, an attacker can request and obtain the contents of arbitrary files on the server, including sensitive configuration files, source code, credential stores, and private keys, provided the application process has permission to read them. The vulnerability is commonly exploited through path traversal sequences (e.g., ../) or absolute file paths (e.g., /etc/passwd). Encoding variations of traversal sequences (e.g., %2e%2e%2f) can also bypass…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-225-03</guid>
    </item>
  </channel>
</rss>
