Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

60 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.1NetApp

Critical [CVE-2026-6100] CPython Vulnerability in NetApp Products

Certain versions of CPython are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6100
Active IQ Unified Manager
Jul 17, 2026
Critical10.0NetApp

Critical [CVE-2026-49261] MariaDB Vulnerability in NetApp Products

MariaDB versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-49261
Unclassified
Jul 10, 2026
Critical9.8NetApp

Critical [CVE-2026-49420] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an attacker to achieve remote code execution in the kernel. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-49420
Unclassified
Jul 10, 2026
Critical9.8NetApp

Critical [CVE-2026-58081 +1] June 2026 FreeBSD iconv Vulnerabilities in NetApp Products

All supported versions of FreeBSD are susceptible to vulnerabilities in iconv encoding modules which when successfully exploited could be used to trigger buffer overflows. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-58081CVE-2026-58082
Unclassified
Jul 10, 2026
Critical9.8NetApp

Critical [CVE-2026-31718] Linux Kernel Vulnerability in NetApp Products

Linux Kernel versions 6.6.32 prior to 6.7, 6.9 prior to 6.12.84, 6.13 prior to 6.18.25, 6.19 prior to 7.0.2, and prior to 7.1-rc1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31718
Unclassified
Jul 3, 2026
Critical9.1NetApp

Critical [CVE-2026-53434] Apache Tomcat Vulnerability in NetApp Products

Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M7 through 10.1.55, and 9.0.83 through 9.0.118 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-53434
Unclassified
Jul 3, 2026
Critical9.2NetApp

Critical [CVE-2026-55200] Libssh2 Vulnerability in NetApp Products

Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-55200
ONTAPActive IQ Unified ManagerONTAP Select
Jul 3, 2026
Critical9.1NetApp

Critical [CVE-2026-55276] Apache Tomcat Vulnerability in NetApp Products

Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0-M1 through 9.0.118, and 8.5.0 through 8.5.100 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-55276
Unclassified
Jul 3, 2026
Critical10.0NetApp

Critical [CVE-2026-44249 +17] June 2026 Apache Netty 4.1 and 4.2 Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Netty. Apache Netty versions prior to 4.1.135.Final and 4.2.0 prior to 4.2.15.Final are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44249CVE-2026-44250CVE-2026-44890+15
Unclassified
Jun 26, 2026
Critical9.8NetApp

Critical [CVE-2026-41417 +10] May 2026 Apache Netty Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Netty. Apache Netty versions prior to 4.1.133.Final and 4.2.0 prior to 4.2.13.Final are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). OnCommand Insight: Affected only by CVE-2026-41417. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-41417CVE-2026-42578CVE-2026-42579+8
OnCommand / Data Infrastructure Insights
Jun 26, 2026
Critical9.6NetApp Updated

Critical [CVE-2026-25680 +5] June 2026 Golang.Org/X/Net Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Golang. Org/X/Net versions prior to 0.55.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-25680CVE-2026-25681CVE-2026-27136+3
Unclassified
Jun 26, 2026
Critical9.1NetApp

Critical [CVE-2026-40971] Spring Boot Vulnerability in NetApp Products

Multiple NetApp products incorporate Spring Boot. Spring Boot versions 3.5.0 prior to 3.5.14 and 4.0.0 prior to 4.0.6 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40971
Unclassified
Jun 26, 2026
Critical9.8NetApp

Critical [CVE-2026-44930] Apache CXF Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache CXF. Apache CXF versions prior to 3.6.11 and 4.0.0 prior to 4.1.6 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44930
Active IQ Unified Manager
Jun 18, 2026
Critical9.8NetApp

Critical [CVE-2026-49875 +10] June 2026 Apache CXF Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache CXF. Apache CXF versions prior to 4.1.7 and 4.2.0 prior to 4.2.2 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-49875CVE-2026-50623CVE-2026-50627+8
Active IQ Unified Manager
Jun 18, 2026
Critical9.1NetApp

Critical [CVE-2026-34182] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp Console Agent Container (adc), NetApp Console Agent Container (cbs), NetApp Console Agent Container (cbs-backend), ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-34182
ONTAPActive IQ Unified ManagerBlueXP / NetApp ConsoleONTAP Select
Jun 17, 2026
Critical10.0NetApp

Critical [CVE-2026-39828 +11] May 2026 Golang Crypto Vulnerabilities in NetApp Products

Golang Crypto versions prior to 0.52.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Astra Control Center, NetApp Console Agent Container (tp-proxy), Trident Protect, Trident Protect Connector. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-39828CVE-2026-39829CVE-2026-39830+9
BlueXP / NetApp ConsoleTrident / Astra
Jun 17, 2026
Critical9.8NetApp

Critical [CVE-2026-29167 +8] June 2026 Apache HTTP Server Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions 2.4.0 through 2.4.67 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). ONTAP 9: Affected only by CVE-2026-44185. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-29167CVE-2026-34355CVE-2026-34356+6
ONTAP
Jun 10, 2026
Critical9.8NetApp

Critical [CVE-2026-43501] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.7-rc1 through 6.6.139, 6.13-rc1 through 6.18.26, 6.19-rc1 through 7.0.3, 6.7-rc1 through 6.12.85, and 7.1-rc1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-43501
Unclassified
Jun 5, 2026
Critical9.8NetApp

Critical [CVE-2026-31607] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31607
Unclassified
Jun 5, 2026
Critical9.8NetApp

Critical [CVE-2025-48431 +10] April 2026 Apache Thrift Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Thrift. Apache Thrift versions prior to 0.23.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-48431CVE-2026-41602CVE-2026-41603+8
Unclassified
May 29, 2026