<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_nozominetworks</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:58 +0000</lastBuildDate>
    <item>
      <title>NN-2026:20-01 — Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc be…</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:20-01</link>
      <description>&lt;p&gt;An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host&amp;#39;s identity, and no option was provided to enable it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host&amp;#39;s identity, and no option was provided to enable it.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:20-01</guid>
      <pubDate>Tue, 08 Sep 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:19-01 — Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:19-01</link>
      <description>&lt;p&gt;An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:19-01</guid>
      <pubDate>Tue, 08 Sep 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:18-01 — Cross-site request forgery in the Guardian/CMC login before 26.3.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:18-01</link>
      <description>&lt;p&gt;A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:18-01</guid>
      <pubDate>Tue, 08 Sep 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:17-01 — Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:17-01</link>
      <description>&lt;p&gt;An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:17-01</guid>
      <pubDate>Tue, 08 Sep 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:16-01 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:16-01</link>
      <description>&lt;p&gt;A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:16-01</guid>
      <pubDate>Tue, 08 Sep 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:15-01 — Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:15-01</link>
      <description>&lt;p&gt;A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:15-01</guid>
      <pubDate>Tue, 11 Aug 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:14-01 — Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:14-01</link>
      <description>&lt;p&gt;The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:14-01</guid>
      <pubDate>Tue, 11 Aug 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:9-01 — Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:9-01</link>
      <description>&lt;p&gt;An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:9-01</guid>
      <pubDate>Tue, 07 Jul 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:8-01 — HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:8-01</link>
      <description>&lt;p&gt;A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:8-01</guid>
      <pubDate>Tue, 07 Jul 2026 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2026:13-01 — Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2026:13-01</link>
      <description>&lt;p&gt;An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2026:13-01</guid>
      <pubDate>Tue, 07 Jul 2026 11:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
