Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical10.0NetApp

Critical [CVE-2026-44249 +17] June 2026 Apache Netty 4.1 and 4.2 Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Netty. Apache Netty versions prior to 4.1.135.Final and 4.2.0 prior to 4.2.15.Final are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44249CVE-2026-44250CVE-2026-44890+15
Unclassified
Jun 26, 2026
Critical9.8NetApp

Critical [CVE-2026-41417 +10] May 2026 Apache Netty Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Netty. Apache Netty versions prior to 4.1.133.Final and 4.2.0 prior to 4.2.13.Final are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). OnCommand Insight: Affected only by CVE-2026-41417. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-41417CVE-2026-42578CVE-2026-42579+8
OnCommand / Data Infrastructure Insights
Jun 26, 2026
Critical9.6NetApp Updated

Critical [CVE-2026-25680 +5] June 2026 Golang.Org/X/Net Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Golang. Org/X/Net versions prior to 0.55.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-25680CVE-2026-25681CVE-2026-27136+3
Unclassified
Jun 26, 2026
Critical9.1Cisco

Critical [CVE-2026-20181 +1] Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Affected products named by the advisory: Identity Services Engine Software.

CVE-2026-20181CVE-2026-20190
ISEIdentity Services Engine
Jun 19, 2026
Critical9.8VMware

Critical [CVE-2026-47846] Bitnami Cassandra container images are affected by a retained default superuser vulnerability.

Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the container initialization script creates the new superuser account but fails to drop the built-in cassandra account in certain scenarios. This leaves the default cassandra:cassandra superuser active as an unintended access path. Affected versions — Container image: 4.0.x prior to 4.0.20-photon-5-r7; 4.1.x prior to 4.1.11-photon-5-r7; 5.0.x prior to 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3.

CVE-2026-47846
Unclassified
Jun 18, 2026
Critical9.2F5

Critical [CVE-2026-42530] NGINX Open Source has a vulnerability in the ngx_http_v3_module module

NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-42530
NGINX
Jun 17, 2026
Critical9.2F5

Critical [CVE-2026-42055] NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-42055
NGINX
Jun 17, 2026
Critical9.1NetApp

Critical [CVE-2026-34182] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp Console Agent Container (adc), NetApp Console Agent Container (cbs), NetApp Console Agent Container (cbs-backend), ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-34182
ONTAPActive IQ Unified ManagerBlueXP / NetApp ConsoleONTAP Select
Jun 17, 2026
Critical10.0NetApp

Critical [CVE-2026-39828 +11] May 2026 Golang Crypto Vulnerabilities in NetApp Products

Golang Crypto versions prior to 0.52.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Astra Control Center, NetApp Console Agent Container (tp-proxy), Trident Protect, Trident Protect Connector. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-39828CVE-2026-39829CVE-2026-39830+9
BlueXP / NetApp ConsoleTrident / Astra
Jun 17, 2026
Critical10.0Cisco Exploited CISA KEV

Critical [CVE-2026-20127] Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVE-2026-20127
SD-WANCatalyst SD-WANvManagevBond
Jun 16, 2026
Critical10.0Cisco Exploited CISA KEV

Critical [CVE-2026-20182] Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The Indicators of Compromise section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. Cisco has released software updates that address this vulnerability.

CVE-2026-20182
SD-WANCatalyst SD-WANvManagevBond
Jun 16, 2026
CriticalVeeam Exploited CISA KEV

Critical [CVE-2020-14040 +33] List of Security Fixes and Improvements in Veeam Kasten for Kubernetes

List of Security Fixes and Improvements in Veeam Kasten for Kubernetes KB ID: 4825 Product: Kasten K10 by Veeam | 3 | 5 | 5.5 | 6 | 6.5 Published: 2026-03-02 Last Modified: Purpose This article aims to provide our customers' security and compliance teams with detailed information on security improvements. - Veeam Kasten for Kubernetes — Release Notes - Upgraded the Prometheus base image to resolve GHSA-hrxh-6v49-42gf - GitHub Advisory - Upgraded Dex image dependencies to resolve multiple Critical and High CVEs - Upgraded to the latest UBI base image to resolve multiple CVEs. - Updated third-party dependencies (gomplate, logger base image) in the dex and logger components to address known vulnerabilities. - Updated the UBI minimal base image to incorporate the latest security fixes. - Improved logging security for Veeam Backup & Replication API credentials and other sensitive values previously written to Kasten logs. It is recommended to upgrade Veeam Kasten and to refresh the token by manually logging out. - Upgraded components of Kasten's bundled Prometheus monitoring stack to resolve multiple CVEs - Updated base images used in the Red Hat Marketplace operator bundle to fix multiple Critical and High CVEs

CVE-2020-14040CVE-2021-23017CVE-2021-33194+31
Backup & ReplicationKasten
Jun 16, 2026
Critical9.0VMware

Critical [CVE-2026-41005] Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML…

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accepted. Encryption uses the SP's public key from published metadata, therefore, any party, not only a trusted IdP, can produce ciphertext UAA can decrypt; successful decryption therefore does not prove the IdP issued the message. Affected versions: Cloud Foundry UAA (uaa_release) 2.0.0 through 78.13.0. Cloud Foundry CF Deployment all versions through 56.1.0.

CVE-2026-41005
Unclassified
Jun 11, 2026
Critical9.3Vendor: HighPalo Alto

Critical [CVE-2026-0274] Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

CVE-2026-0274
Cortex
Jun 10, 2026
Critical9.2QNAP

Critical [CVE-2025-66276] QuTS hero: QuTS hero is not affected.

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later Affected product named by the advisory: QTS 4.3.x.

CVE-2025-66276
QTS
Jun 10, 2026
Critical9.8NetApp

Critical [CVE-2026-29167 +8] June 2026 Apache HTTP Server Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions 2.4.0 through 2.4.67 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). ONTAP 9: Affected only by CVE-2026-44185. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-29167CVE-2026-34355CVE-2026-34356+6
ONTAP
Jun 10, 2026
Critical9.1Fortinet Exploited CISA KEV

Critical [CVE-2026-25089] Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

CVE-2026-25089
FortiSandbox
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-45657] Windows Kernel Remote Code Execution Vulnerability

Windows Kernel Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-45657
Windows Server
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-47291] HTTP.sys Remote Code Execution Vulnerability

HTTP.sys Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-47291
Windows Server
Jun 9, 2026
Critical9.1Vendor: HighMS Server

Critical [CVE-2026-45602] Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability

Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45602
Windows Server
Jun 9, 2026