<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 21:45:50 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-28198 — Privilege Escalation via Cryptographic Signature Verification Bypass in NetBackup Flex OS Shell</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-28198</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Cohesity NetBackup Flex OS&lt;/p&gt;
&lt;p&gt;An authenticated, low-privileged user with access to the NetBackup Flex 
OS management shell could bypass the cryptographic signature 
verification step of a privileged support command by supplying a 
specially formed access credential. Successful exploitation grants the 
attacker an unrestricted root shell with full control over the Flex 
appliance host and all hosted containers, completely compromising 
confidentiality, integrity, and availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Cohesity NetBackup Flex OS&lt;/p&gt;
&lt;p&gt;An authenticated, low-privileged user with access to the NetBackup Flex 
OS management shell could bypass the cryptographic signature 
verification step of a privileged support command by supplying a 
specially formed access credential. Successful exploitation grants the 
attacker an unrestricted root shell with full control over the Flex 
appliance host and all hosted containers, completely compromising 
confidentiality, integrity, and availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-28198</guid>
    </item>
  </channel>
</rss>
