<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:14:01 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:58555 — Moderate: NetworkManager security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:58555</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: NetworkManager, AlmaLinux:8: NetworkManager-adsl, AlmaLinux:8: NetworkManager-bluetooth, AlmaLinux:8: NetworkManager-cloud-setup, AlmaLinux:8: NetworkManager-config-connectivity-redhat, AlmaLinux:8: NetworkManager-config-server, AlmaLinux:8: NetworkManager-dispatcher-routing-rules, AlmaLinux:8: NetworkManager-initscripts-updown, AlmaLinux:8: NetworkManager-libnm, AlmaLinux:8: NetworkManager-libnm-devel and 6 more&lt;/p&gt;
&lt;p&gt;NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: NetworkManager, AlmaLinux:8: NetworkManager-adsl, AlmaLinux:8: NetworkManager-bluetooth, AlmaLinux:8: NetworkManager-cloud-setup, AlmaLinux:8: NetworkManager-config-connectivity-redhat, AlmaLinux:8: NetworkManager-config-server, AlmaLinux:8: NetworkManager-dispatcher-routing-rules, AlmaLinux:8: NetworkManager-initscripts-updown, AlmaLinux:8: NetworkManager-libnm, AlmaLinux:8: NetworkManager-libnm-devel and 6 more&lt;/p&gt;
&lt;p&gt;NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:58555</guid>
    </item>
    <item>
      <title>EUVD-2026-375530</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-375530</link>
      <description>EUVD-2026-375530</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-375530</guid>
    </item>
    <item>
      <title>fkie_cve-2026-10805</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10805</link>
      <description>&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;#39;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;#39;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-10805</guid>
    </item>
    <item>
      <title>GHSA-rwc7-7qq8-w477</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rwc7-7qq8-w477</link>
      <description>&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;#39;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;#39;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rwc7-7qq8-w477</guid>
    </item>
    <item>
      <title>OESA-2026-2822 — NetworkManager security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2822</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: NetworkManager&lt;/p&gt;
&lt;p&gt;NetworkManager attempts to keep an active network connection available at all times.  The point of NetworkManager is to make networking configuration and setup as painless and automatic as possible. If using DHCP, NetworkManager is intended to replace default routes, obtain IP addresses from a DHCP server, and change name servers whenever it sees fit.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;amp;apos;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.(CVE-2026-10805)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: NetworkManager&lt;/p&gt;
&lt;p&gt;NetworkManager attempts to keep an active network connection available at all times.  The point of NetworkManager is to make networking configuration and setup as painless and automatic as possible. If using DHCP, NetworkManager is intended to replace default routes, obtain IP addresses from a DHCP server, and change name servers whenever it sees fit.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;amp;apos;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.(CVE-2026-10805)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2822</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11693-1 — NetworkManager-1.56.1-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11693-1</link>
      <description>&lt;p&gt;NetworkManager-1.56.1-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NetworkManager-1.56.1-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11693-1</guid>
    </item>
    <item>
      <title>RHSA-2026:61239 — Red Hat Security Advisory: NetworkManager security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:61239</link>
      <description>&lt;p&gt;NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:61239</guid>
    </item>
    <item>
      <title>RLSA-2026:58555 — Moderate: NetworkManager security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:58555</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: NetworkManager&lt;/p&gt;
&lt;p&gt;NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: NetworkManager&lt;/p&gt;
&lt;p&gt;NetworkManager is a system network service that manages network devices and connections, attempting to keep active network connectivity when available. Its capabilities include managing Ethernet, wireless, mobile broadband (WWAN), and PPPoE devices, as well as providing VPN integration with a variety of different VPN services.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend (CVE-2026-10805)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:58555</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23475-1 — Security update for NetworkManager</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23475-1</link>
      <description>&lt;p&gt;Security update for NetworkManager&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for NetworkManager&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23475-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-10805</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10805</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: network-manager, Ubuntu:18.04:LTS: network-manager, Ubuntu:20.04:LTS: network-manager, Ubuntu:22.04:LTS: network-manager, Ubuntu:24.04:LTS: network-manager, Ubuntu:25.10: network-manager, Ubuntu:26.04:LTS: network-manager&lt;/p&gt;
&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;#39;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: network-manager, Ubuntu:18.04:LTS: network-manager, Ubuntu:20.04:LTS: network-manager, Ubuntu:22.04:LTS: network-manager, Ubuntu:24.04:LTS: network-manager, Ubuntu:25.10: network-manager, Ubuntu:26.04:LTS: network-manager&lt;/p&gt;
&lt;p&gt;A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager&amp;#39;s dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10805</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2977 — Red Hat Enterprise Linux (NetworkManager): Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2977</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (NetworkManager) ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (NetworkManager) ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2977</guid>
    </item>
  </channel>
</rss>
