<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 16:12:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278452</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278452</link>
      <description>EUVD-2026-278452</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278452</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34227</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34227</link>
      <description>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator&amp;#39;s own browser. This issue has been patched in version 1.7.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator&amp;#39;s own browser. This issue has been patched in version 1.7.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34227</guid>
    </item>
    <item>
      <title>GHSA-6fpf-248c-m7wm — Sliver One-Click Remote Access: Insecure CORS &amp; Unauthenticated MCP Interface</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6fpf-248c-m7wm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bishopfox/sliver&lt;/p&gt;
&lt;p&gt;A single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, `ntds.dit`) or destroying the entire compromised infrastructure, entirely through the operator&amp;#39;s own browser.&lt;/p&gt;
&lt;p&gt;## Description
The Sliver MCP server runs inside the Sliver Client and binds an unauthenticated HTTP and SSE interface to `localhost:8080` by default. The service returns a permissive `Access-Control-Allow-Origin: *` header on all responses.&lt;/p&gt;
&lt;p&gt;Because this server is client-side, the attack surface is distributed across every individual operator in the operation. Any arbitrary website can issue cross-origin requests and interact with the MCP interface via an operator&amp;#39;s browser, no credentials required.&lt;/p&gt;
&lt;p&gt;If the interface is misconfigured to bind to all interfaces (`0.0.0.0`), the vulnerability escalates from a client-side CSRF/CORS issue to direct, unauthenticated remote access from any actor on the network.&lt;/p&gt;
&lt;p&gt;## Exposed Methods
Exploitation grants unauthorized access to the following MCP tools:
- `list_sessions_and_beacons`
- `fs_ls`, `fs_pwd`, `fs_cd`
- `fs_cat`
- `fs_rm`, `fs_mv`, `fs_cp`, `fs_mkdir`
- `fs_chmod`, `fs_chown`&lt;/p&gt;
&lt;p&gt;## PoC 
1. Start the Sliver client with MCP enabled (default `localhost:8080`)
2. Open a browser and load a page containing the [Proof of Concept JavaScript](https://github.com/skoveit/CVE-2026-34227).
3. Observe that the page successfully lists s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/bishopfox/sliver&lt;/p&gt;
&lt;p&gt;A single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, `ntds.dit`) or destroying the entire compromised infrastructure, entirely through the operator&amp;#39;s own browser.&lt;/p&gt;
&lt;p&gt;## Description
The Sliver MCP server runs inside the Sliver Client and binds an unauthenticated HTTP and SSE interface to `localhost:8080` by default. The service returns a permissive `Access-Control-Allow-Origin: *` header on all responses.&lt;/p&gt;
&lt;p&gt;Because this server is client-side, the attack surface is distributed across every individual operator in the operation. Any arbitrary website can issue cross-origin requests and interact with the MCP interface via an operator&amp;#39;s browser, no credentials required.&lt;/p&gt;
&lt;p&gt;If the interface is misconfigured to bind to all interfaces (`0.0.0.0`), the vulnerability escalates from a client-side CSRF/CORS issue to direct, unauthenticated remote access from any actor on the network.&lt;/p&gt;
&lt;p&gt;## Exposed Methods
Exploitation grants unauthorized access to the following MCP tools:
- `list_sessions_and_beacons`
- `fs_ls`, `fs_pwd`, `fs_cd`
- `fs_cat`
- `fs_rm`, `fs_mv`, `fs_cp`, `fs_mkdir`
- `fs_chmod`, `fs_chown`&lt;/p&gt;
&lt;p&gt;## PoC 
1. Start the Sliver client with MCP enabled (default `localhost:8080`)
2. Open a browser and load a page containing the [Proof of Concept JavaScript](https://github.com/skoveit/CVE-2026-34227).
3. Observe that the page successfully lists s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6fpf-248c-m7wm</guid>
    </item>
  </channel>
</rss>
