Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-6726] Trusted Platform Module 2.0 Vulnerability in NetApp Products
The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which when exploited could allow improper reuse of object slots between key/data objects and hash contexts, enabling an attacker to falsify TPM attestations and credentials. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.
High [CVE-2026-58224] Samba Vulnerability in NetApp Products
Samba versions 4.2 and higher are susceptible to a vulnerability which when successfully exploited could result in Denial of Service (DoS) and possible limited disclosure of adjacent memory allocations. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp states there is no workaround available at this time.
High [CVE-2026-6727] Trusted Platform Module 2.0 Vulnerability in NetApp Products
The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which exposes a timing side-channel in RSA OAEP decryption, enabling an attacker to decrypt sensitive blobs (import blobs, credential blobs, and session salts) encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), or to falsify TPM 2.0 Attestation Keys. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.
High [CVE-2026-29036] cJSON Vulnerability in NetApp Products
cJSON versions 1.5.0 through 1.7.19 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-6949] Samba Vulnerability in NetApp Products
Samba versions 4.0 and higher are susceptible to a vulnerability which when successfully exploited could lead to a large out-of-bounds write causing the server to crash. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-58221] Samba Vulnerability in NetApp Products
Samba AD DC versions 4.0.0 and higher are susceptible to a vulnerability which when successfully exploited permits a domain takeover by allowing low-privilege authenticated LDAP access modifications to internal LDB special DNs. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-14456] OpenSSL Vulnerability in NetApp Products
OpenSSL versions 4.0, 3.6, and 3.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-58043] Node.js Vulnerability in NetApp Products
Node.js versions 22.x through 22.23.1, 24.x through 24.18.0, and 26.x through 26.5.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-72848] Server-Side Request Forgery and Information Disclosure via nested sitemap entries
Server-Side Request Forgery and Information Disclosure via nested sitemap entries. Red Hat rates this important (CVSS 8.6). Weakness: CWE-918. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-69519] Azure Stack HCI Information Disclosure Vulnerability
Azure Stack HCI Information Disclosure Vulnerability
High [CVE-2026-15679] Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data
Hugging Face PyTorch Image Models: Remote Code Execution via Deserialization of Untrusted Data. Red Hat rates this important (CVSS 8.8). Weakness: CWE-502. Affected products named by the advisory: Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-77176] Insufficient validation of CreateContainer mount and storage rules in genpolicy
Insufficient validation of CreateContainer mount and storage rules in genpolicy. Red Hat rates this important (CVSS 8.1). Weakness: CWE-73. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
High [CVE-2026-61898] Arbitrary code execution via shell injection
Arbitrary code execution via shell injection. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78.
High [CVE-2026-61897] Local privilege escalation via incomplete privilege drop in language helper scripts
Local privilege escalation via incomplete privilege drop in language helper scripts. Red Hat rates this important (CVSS 7.8). Weakness: CWE-273.
High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
High [CVE-2026-76047] Arbitrary code execution via type confusion in V8
Arbitrary code execution via type confusion in V8. Red Hat rates this important (CVSS 8.3). Weakness: CWE-843.
High [CVE-2026-76045] Arbitrary code execution via use-after-free
Arbitrary code execution via use-after-free. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-76043] Arbitrary code execution via incorrect calculation in HTML processing
Arbitrary code execution via incorrect calculation in HTML processing. Red Hat rates this important (CVSS 8.8). Weakness: CWE-190.
High [CVE-2026-76039] Information disclosure via incorrect reference resolution
Information disclosure via incorrect reference resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-386.
High [CVE-2026-76040] Arbitrary code execution via use-after-free vulnerability
Arbitrary code execution via use-after-free vulnerability. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.