<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:50:14 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-11622</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-11622</link>
      <description>bdu:2026-11622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-11622</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1000 — De multiples vulnérabilités ont été découvertes dans Microsoft Office. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1000</link>
      <description>certfr-2026-avi-1000</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1000</guid>
    </item>
    <item>
      <title>EUVD-2026-378709</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-378709</link>
      <description>EUVD-2026-378709</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-378709</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66806</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66806</link>
      <description>&lt;p&gt;Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66806</guid>
    </item>
    <item>
      <title>GHSA-vr2p-489v-8hm2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vr2p-489v-8hm2</link>
      <description>&lt;p&gt;Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vr2p-489v-8hm2</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-66806 — Microsoft Office Word Information Disclosure Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-66806</link>
      <description>msrc_CVE-2026-66806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-66806</guid>
    </item>
    <item>
      <title>NCSC-2026-0286 — Kwetsbaarheden verholpen in Microsoft Office</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0286</link>
      <description>NCSC-2026-0286</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0286</guid>
    </item>
    <item>
      <title>RHSA-2026:59579 — Red Hat Security Advisory: multicluster engine for Kubernetes v2.6.14 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:59579</link>
      <description>&lt;p&gt;golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token form-data: form-data: Form field override via CRLF injection provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing cluster-curator-controller: cluster-curator-controller: namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token form-data: form-data: Form field override via CRLF injection provider-credential-controller: provider-credential-controller: cross-namespace credential propagation via attacker-controlled copiedFrom labels bypasses authorization crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs find-my-way: find-my-way: Denial of Service vulnerability in HTTP/2 server ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification cluster-proxy-addon: cluster-proxy-addon: unauthenticated SSRF to arbitrary managed-cluster services via public…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:59579</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2762 — Microsoft Office Produkte: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2762</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Office Produkte ausnutzen, um Dateien zu manipulieren, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Office Produkte ausnutzen, um Dateien zu manipulieren, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2762</guid>
    </item>
  </channel>
</rss>
