<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:47:20 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:9683 — Important: java-1.8.0-openjdk security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:9683</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: java-1.8.0-openjdk, AlmaLinux:8: java-1.8.0-openjdk-accessibility, AlmaLinux:8: java-1.8.0-openjdk-accessibility-fastdebug, AlmaLinux:8: java-1.8.0-openjdk-accessibility-slowdebug, AlmaLinux:8: java-1.8.0-openjdk-demo, AlmaLinux:8: java-1.8.0-openjdk-demo-fastdebug, AlmaLinux:8: java-1.8.0-openjdk-demo-slowdebug, AlmaLinux:8: java-1.8.0-openjdk-devel, AlmaLinux:8: java-1.8.0-openjdk-devel-fastdebug, AlmaLinux:8: java-1.8.0-openjdk-devel-slowdebug and 27 more&lt;/p&gt;
&lt;p&gt;The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* JDK: Enhance crypto algorithm support (CVE-2026-22007)
  * JDK: Improve Kerberos credentialing (CVE-2026-22013)
  * JDK: Enhance Path Factories Redux (CVE-2026-22016)
  * JDK: Enhance Zip file reading (CVE-2026-22018)
  * JDK: Enhance certificate chain validation (CVE-2026-22021)
  * JDK: Updating FreeType 2.14.1 (CVE-2026-23865)
  * JDK: Enhance key generation (CVE-2026-34268)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: java-1.8.0-openjdk, AlmaLinux:8: java-1.8.0-openjdk-accessibility, AlmaLinux:8: java-1.8.0-openjdk-accessibility-fastdebug, AlmaLinux:8: java-1.8.0-openjdk-accessibility-slowdebug, AlmaLinux:8: java-1.8.0-openjdk-demo, AlmaLinux:8: java-1.8.0-openjdk-demo-fastdebug, AlmaLinux:8: java-1.8.0-openjdk-demo-slowdebug, AlmaLinux:8: java-1.8.0-openjdk-devel, AlmaLinux:8: java-1.8.0-openjdk-devel-fastdebug, AlmaLinux:8: java-1.8.0-openjdk-devel-slowdebug and 27 more&lt;/p&gt;
&lt;p&gt;The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* JDK: Enhance crypto algorithm support (CVE-2026-22007)
  * JDK: Improve Kerberos credentialing (CVE-2026-22013)
  * JDK: Enhance Path Factories Redux (CVE-2026-22016)
  * JDK: Enhance Zip file reading (CVE-2026-22018)
  * JDK: Enhance certificate chain validation (CVE-2026-22021)
  * JDK: Updating FreeType 2.14.1 (CVE-2026-23865)
  * JDK: Enhance key generation (CVE-2026-34268)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:9683</guid>
    </item>
    <item>
      <title>bdu:2026-06615</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06615</link>
      <description>bdu:2026-06615</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06615</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-23865</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-23865</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: freetype, Alpaquita:23: openjdk-nik-23-17, Alpaquita:23: openjdk-nik-23-21, Alpaquita:23: openjdk-nik-25-25, Alpaquita:23: openjdk11, Alpaquita:23: openjdk11-container-jre, Alpaquita:23: openjdk11-lite, Alpaquita:23: openjdk11-perf, Alpaquita:23: openjdk17, Alpaquita:23: openjdk17-container-jre and 115 more&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: freetype, Alpaquita:23: openjdk-nik-23-17, Alpaquita:23: openjdk-nik-23-21, Alpaquita:23: openjdk-nik-25-25, Alpaquita:23: openjdk11, Alpaquita:23: openjdk11-container-jre, Alpaquita:23: openjdk11-lite, Alpaquita:23: openjdk11-perf, Alpaquita:23: openjdk17, Alpaquita:23: openjdk17-container-jre and 115 more&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-23865</guid>
    </item>
    <item>
      <title>BIT-java-2026-23865</title>
      <link>https://cve.radiocsirt.org/vuln/bit-java-2026-23865</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: java&lt;/p&gt;
&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: java&lt;/p&gt;
&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-java-2026-23865</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0274 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0274</link>
      <description>certfr-2026-avi-0274</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0274</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KV09488 — Security fixes for CVE-2026-23865, CVE-2026-23868, CVE-2026-24281, CVE-2026-24308, CVE-2026-34479, CVE-2026-42577, ghsa…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-kv09488</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: solr&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the solr package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: solr&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the solr package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-kv09488</guid>
    </item>
    <item>
      <title>EUVD-2026-274162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274162</link>
      <description>EUVD-2026-274162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274162</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23865</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23865</link>
      <description>&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23865</guid>
    </item>
    <item>
      <title>GHSA-878v-mxg6-vj8f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-878v-mxg6-vj8f</link>
      <description>&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-878v-mxg6-vj8f</guid>
    </item>
    <item>
      <title>jvndb-2026-016982</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-016982</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been found in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center.&#13;
&#13;
CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been found in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center.&#13;
&#13;
CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-23865, CVE-2026-34268, CVE-2026-34282&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-016982</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-23865 — An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.1…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-23865</link>
      <description>msrc_CVE-2026-23865</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-23865</guid>
    </item>
    <item>
      <title>OESA-2026-1574 — freetype security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: freetype&lt;/p&gt;
&lt;p&gt;FreeType is written in C, designed to be small,efficient, highly customizable, and portable while capable of producing high-quality output (glyph images) of most vector and bitmap font formats&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.(CVE-2026-23865)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: freetype&lt;/p&gt;
&lt;p&gt;FreeType is written in C, designed to be small,efficient, highly customizable, and portable while capable of producing high-quality output (glyph images) of most vector and bitmap font formats&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.(CVE-2026-23865)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1574</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10289-1 — freetype2-devel-2.14.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10289-1</link>
      <description>&lt;p&gt;freetype2-devel-2.14.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;freetype2-devel-2.14.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10289-1</guid>
    </item>
    <item>
      <title>RHSA-2026:22328 — Red Hat Security Advisory: java-21-ibm-semeru-certified-jdk security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:22328</link>
      <description>&lt;p&gt;Eclipse Open9J: Denial of Service in JITServer via crafted TCP message openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04) openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04) openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04) openjdk: Enhance certificate chain validation (Oracle CPU 2026-04) freetype: Information disclosure or denial of service via specially crafted font files openjdk: Enhance key generation (Oracle CPU 2026-04) openjdk: Enhance TLS connection handling (Oracle CPU 2026-04)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eclipse Open9J: Denial of Service in JITServer via crafted TCP message openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04) openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04) openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04) openjdk: Enhance certificate chain validation (Oracle CPU 2026-04) freetype: Information disclosure or denial of service via specially crafted font files openjdk: Enhance key generation (Oracle CPU 2026-04) openjdk: Enhance TLS connection handling (Oracle CPU 2026-04)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:22328</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1703-1 — Security update for java-11-openjdk</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1703-1</link>
      <description>&lt;p&gt;Security update for java-11-openjdk&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for java-11-openjdk&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1703-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-23865</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23865</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openjdk-8, Ubuntu:16.04:LTS: openjdk-9, Ubuntu:Pro:18.04:LTS: openjdk-lts, Ubuntu:Pro:18.04:LTS: openjdk-17, Ubuntu:Pro:18.04:LTS: openjdk-8, Ubuntu:Pro:20.04:LTS: openjdk-lts, Ubuntu:20.04:LTS: openjdk-13, Ubuntu:20.04:LTS: openjdk-16, Ubuntu:Pro:20.04:LTS: openjdk-17, Ubuntu:Pro:20.04:LTS: openjdk-21 and 32 more&lt;/p&gt;
&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openjdk-8, Ubuntu:16.04:LTS: openjdk-9, Ubuntu:Pro:18.04:LTS: openjdk-lts, Ubuntu:Pro:18.04:LTS: openjdk-17, Ubuntu:Pro:18.04:LTS: openjdk-8, Ubuntu:Pro:20.04:LTS: openjdk-lts, Ubuntu:20.04:LTS: openjdk-13, Ubuntu:20.04:LTS: openjdk-16, Ubuntu:Pro:20.04:LTS: openjdk-17, Ubuntu:Pro:20.04:LTS: openjdk-21 and 32 more&lt;/p&gt;
&lt;p&gt;An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-23865</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0565 — FreeType: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0565</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FreeType ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in FreeType ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0565</guid>
    </item>
  </channel>
</rss>
