Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

569 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.2QNAP

Critical [CVE-2025-66276] QuTS hero: QuTS hero is not affected.

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later Affected product named by the advisory: QTS 4.3.x.

CVE-2025-66276
QTS
Jun 10, 2026
Critical9.8NetApp

Critical [CVE-2026-29167 +8] June 2026 Apache HTTP Server Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions 2.4.0 through 2.4.67 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). ONTAP 9: Affected only by CVE-2026-44185. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-29167CVE-2026-34355CVE-2026-34356+6
ONTAP
Jun 10, 2026
Critical9.9Ivanti

Critical [CVE-2026-10523] Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

CVE-2026-10523
Sentry
Jun 9, 2026
Critical10.0Ivanti Exploited CISA KEV

Critical [CVE-2026-10520] OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

CVE-2026-10520
Sentry
Jun 9, 2026
Critical9.1Fortinet Exploited CISA KEV

Critical [CVE-2026-25089] Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00

CVE-2026-25089
FortiSandbox
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-45657] Windows Kernel Remote Code Execution Vulnerability

Windows Kernel Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-45657
Windows Server
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-47291] HTTP.sys Remote Code Execution Vulnerability

HTTP.sys Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-47291
Windows Server
Jun 9, 2026
Critical9.1Vendor: HighMS Server

Critical [CVE-2026-45602] Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability

Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-45602
Windows Server
Jun 9, 2026
Critical9.6Vendor: HighMS Server

Critical [CVE-2026-42904] Windows TCP/IP Elevation of Privilege Vulnerability

Windows TCP/IP Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2022; Windows Server 2025.

CVE-2026-42904
Windows Server
Jun 9, 2026
Critical9.8MS Server

Critical [CVE-2026-44815] DHCP Client Service Remote Code Execution Vulnerability

DHCP Client Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.

CVE-2026-44815
Windows Server
Jun 9, 2026
Critical9.4Veeam

Critical [CVE-2026-44963] Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854

Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 KB ID: 4869 Product: Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 Published: 2026-06-09 Last Modified: 2026-06-09 All vulnerabilities documented in this article were resolved in Veeam Backup & Replication 12.3.2.4854.

CVE-2026-44963
Backup & Replication
Jun 9, 2026
Critical9.3Check Point Exploited CISA KEV

Critical [CVE-2026-50751] User Authentication Bypass in VPN Remote Access and Mobile Access

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Affected products named by the advisory: Quantum Security Gateway; Spark Firewalls.

CVE-2026-50751
Quantum Gateway / Gaia
Jun 8, 2026
Critical9.8NetApp

Critical [CVE-2026-43501] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.7-rc1 through 6.6.139, 6.13-rc1 through 6.18.26, 6.19-rc1 through 7.0.3, 6.7-rc1 through 6.12.85, and 7.1-rc1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-43501
Unclassified
Jun 5, 2026
Critical9.8NetApp

Critical [CVE-2026-31607] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31607
Unclassified
Jun 5, 2026
Critical9.1MS Server

Critical [CVE-2026-48579] Microsoft Exchange Online Information Disclosure Vulnerability

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

CVE-2026-48579
Exchange Server
Jun 4, 2026
Critical10.0VMware

Critical [CVE-2026-40965] Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure.

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification but incorrectly exposes private key components for EC keys. The vulnerability affects deployments using EC keys for JWT token signing.

CVE-2026-40965
Unclassified
Jun 1, 2026
Critical9.8NetApp

Critical [CVE-2025-48431 +10] April 2026 Apache Thrift Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Thrift. Apache Thrift versions prior to 0.23.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-48431CVE-2026-41602CVE-2026-41603+8
Unclassified
May 29, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0265] PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

CVE-2026-0265 PAN-OS: Authentication Bypass with Cloud Authentication Service (CAS) enabled

CVE-2026-0265
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0264] PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

CVE-2026-0264 PAN-OS: Heap-Based Buffer Overflow in DNS Proxy and DNS Server Allows Unauthenticated Remote Code Execution

CVE-2026-0264
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026
Critical9.2Vendor: HighPalo Alto

Critical [CVE-2026-0263] PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing

CVE-2026-0263 PAN-OS: Remote Code Execution (RCE) in IKEv2 Processing

CVE-2026-0263
PAN-OSFirewallPAN-OS / Panorama
May 28, 2026