<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 17:47:16 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-32666 — Automated Logic WebCTRL Premium Server Authentication Bypass by Spoofing</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-32666</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Automated Logic WebCTRL Premium Server&lt;/p&gt;
&lt;p&gt;WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack
 of network layer authentication. WebCTRL does not implement additional 
validation of BACnet traffic so an attacker with network access could 
spoof BACnet packets directed at either the WebCTRL server or associated
 AutomatedLogic controllers. Spoofed packets may be processed as 
legitimate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Automated Logic WebCTRL Premium Server&lt;/p&gt;
&lt;p&gt;WebCTRL systems that communicate over BACnet inherit the protocol&amp;#39;s lack
 of network layer authentication. WebCTRL does not implement additional 
validation of BACnet traffic so an attacker with network access could 
spoof BACnet packets directed at either the WebCTRL server or associated
 AutomatedLogic controllers. Spoofed packets may be processed as 
legitimate.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-32666</guid>
    </item>
  </channel>
</rss>
