Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8NetApp

High [CVE-2026-43503] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions 3.9-rc1 through 5.10.256, 5.11-rc1 through 5.15.207, 5.16-rc1 through 6.1.173, 6.13-rc1 through 6.18.32, 6.19-rc1 through 7.0.9, 6.2-rc1 through 6.6.140, 6.7-rc1 through 6.12.90 and 7.1-rc1 through 7.1-rc4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-43503
AFF / ASA / FASElement Software
Jul 10, 2026
High7.8NetApp

High [CVE-2026-46242] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions 5.15.209 prior to 5.16, 6.1.175 prior to 6.2, 6.4 prior to 6.18.33, and 6.19 prior to 7.0.10 are susceptible to a vulnerability referred to as BadEpoll which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-46242
Unclassified
Jul 10, 2026
High7.8NetApp

High [CVE-2026-49418] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local attacker to trigger a use-after-free in the kernel and possibly escalate their privileges. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-49418
Unclassified
Jul 10, 2026
High7.8NetApp

High [CVE-2026-49419] FreeBSD Vulnerability in NetApp Products

FreeBSD 15.0 and later are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user to cause a panic or elevate their privilege. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-49419
Unclassified
Jul 10, 2026
High7.5NetApp

High [CVE-2026-49423] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited by a remote TLS peer with control of TCP segmentation could result in a kernel panic. Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-49423
Unclassified
Jul 10, 2026
High7.8NetApp

High [CVE-2026-49422] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user to escalate their privilege. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-49422
Unclassified
Jul 10, 2026
High7.8NetApp

High [CVE-2026-53359] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions 2.6.36-rc1 through 6.1.176, 6.13-rc1 through 6.18.37, 6.19-rc1 through 7.1.2, 6.2-rc1 through 6.6.143 and 6.7-rc1 through 6.12.94 are susceptible to a vulnerability referred to as Januscape which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-53359
AFF / ASA / FASElement Software
Jul 10, 2026
High7.8NetApp

High [CVE-2026-49415] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user to modify the address space of a SUID binary before its credentials are elevated, potentially gaining full control of the affected system. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-49415
Unclassified
Jul 10, 2026
High7.3Juniper

High [CVE-2026-57028] Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion. Due to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized access to the license management. This issue affects all Junos OS Evolved versions before 23.2R2-EVO.

CVE-2026-57028
JunosJunos OS Evolved
Jul 9, 2026
High7.5Juniper

High [CVE-2026-57026] Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart

An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX Series with SPC3 and SRX Series: - all versions before 23.2R2-S7, - 23.4 versions before 23.4R2-S8, - 25.4 versions before 25.4R1-S2. Affected products named by the advisory: MX. Affected products named by the advisory: MX.

CVE-2026-57026
SRXFirewallRoutersJunos
Jul 9, 2026
High7.5Juniper

High [CVE-2026-57023] Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS)

An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS). When TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered. This issue affects Junos OS on MX with SPC3, and SRX Series: - 23.4 versions before 23.4R2-S7, - 24.2 versions before 24.2R2-S4, This issue does not affect releases before 23.4R1. Affected products named by the advisory: MX. Affected products named by the advisory: MX.

CVE-2026-57023
SRXFirewallRoutersJunos
Jul 9, 2026
High7.5Apache

High [CVE-2026-57111] Apache Helix: Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest…

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.

CVE-2026-57111
Unclassified
Jul 9, 2026
High7.5VMware

High [CVE-2026-47840] network attacker positioned between UAA and its LDAP directory

A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.

CVE-2026-47840
Unclassified
Jul 9, 2026
High7.5VMware

High [CVE-2026-47831] BOSH: Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemce…

Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVE-2026-47831
Tanzu / Spring
Jul 9, 2026
High8.8VMware

High [CVE-2026-47830] BOSH: Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privile…

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwrite C:\bosh\service_wrapper.exe or C:\bosh\bosh-agent.exe and gain NT AUTHORITY\SYSTEM on the next service restart or reboot. This can lead to full host control. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.

CVE-2026-47830
Tanzu / Spring
Jul 9, 2026
High7.8VMware

High [CVE-2026-47829] BOSH: Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locall…

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.

CVE-2026-47829
Workstation & FusionTanzu / Spring
Jul 9, 2026
High8.8VMware

High [CVE-2026-47828] BOSH: During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the n…

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker can terminate the TLS connection, harvest the Basic-auth credentials, and read the rendered-templates archive containing every bootstrap secret for the new BOSH Director, then replay the credentials against the real VM's agent for root code execution. Affected versions: bosh-cli versions prior to v7.10.4.

CVE-2026-47828
Tanzu / Spring
Jul 9, 2026
High7.8VMware

High [CVE-2026-41857] BOSH: compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the…

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

CVE-2026-41857
Workstation & FusionTanzu / Spring
Jul 9, 2026
High8.7GitLab

High [CVE-2026-6896] GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.

CVE-2026-6896
GitLab CE / EE
Jul 8, 2026
High7.5GitLab

High [CVE-2026-15167] GitLab: DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service

DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service Affected product named by the advisory: GitLab.

CVE-2026-15167
Unclassified
Jul 8, 2026