<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:06:18 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09060</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09060</link>
      <description>bdu:2025-09060</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09060</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0496 — De multiples vulnérabilités ont été découvertes dans les produits Fortinet. Certaines d'entre elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0496</link>
      <description>certfr-2025-avi-0496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0496</guid>
    </item>
    <item>
      <title>EUVD-2026-350956</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-350956</link>
      <description>EUVD-2026-350956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-350956</guid>
    </item>
    <item>
      <title>fkie_cve-2025-22862</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22862</link>
      <description>&lt;p&gt;An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2.0 through 7.2.11, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-22862</guid>
    </item>
    <item>
      <title>GHSA-w9rm-93rw-98gq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w9rm-93rw-98gq</link>
      <description>&lt;p&gt;An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2 all versions, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS 7.4.0 through 7.4.7, 7.2 all versions, 7.0.6 and above; and FortiProxy 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0.5 and above may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w9rm-93rw-98gq</guid>
    </item>
    <item>
      <title>ICSA-25-135-01 — Siemens RUGGEDCOM APE1808 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-135-01</link>
      <description>&lt;p&gt;An insufficiently protected credentials vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server. An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out. A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets. An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices. An Authentication Bypass Using an Alternate Path or Channel vulnerability in FortiOS and FortiProxy may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component. An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An insufficiently protected credentials vulnerability in FortiOS may allow a privileged authenticated attacker to retrieve LDAP credentials via modifying the LDAP server IP address in the FortiOS configuration to point to a malicious attacker-controlled server. An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal to log in again, although the session has expired or was logged out. A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets. An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6.0, version 7.4.7 and below, 7.0 all versions, 6.4 all versions and FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versions, 7.0 all versions may allow a remote unauthenticated user to bypass the DNS filter via Apple devices. An Authentication Bypass Using an Alternate Path or Channel vulnerability in FortiOS and FortiProxy may allow an authenticated attacker to elevate their privileges via triggering a malicious Webhook action in the Automation Stitch component. An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-135-01</guid>
    </item>
    <item>
      <title>SSA-864900 — SSA-864900: Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-864900</link>
      <description>&lt;p&gt;Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products.&lt;/p&gt;
&lt;p&gt;Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-864900</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1295 — Fortinet FortiOS und FortiProxy: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1295</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fortinet FortiOS und Fortinet FortiProxy ausnutzen, um Dateien zu manipulieren, um falsche Informationen darzustellen, und um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Fortinet FortiOS und Fortinet FortiProxy ausnutzen, um Dateien zu manipulieren, um falsche Informationen darzustellen, und um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1295</guid>
    </item>
  </channel>
</rss>
