Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.2F5

High [CVE-2026-20916] BIG-IQ: authenticated iControl REST user with low privileges

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-20916
BIG-IQ
May 13, 2026
High7.2Vendor: MediumPalo Alto

High [CVE-2026-0241] Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities

CVE-2026-0241 Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities

CVE-2026-0241
Unclassified
May 13, 2026
High8.6Vendor: MediumPalo Alto

High [CVE-2026-0242] Trust Protection Foundation: SQL Injection Vulnerability

CVE-2026-0242 Trust Protection Foundation: SQL Injection Vulnerability

CVE-2026-0242
Unclassified
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0246] Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246 Prisma Access Agent: Local Privilege Escalation Vulnerability

CVE-2026-0246
Prisma Access
May 13, 2026
High8.5Vendor: MediumPalo Alto

High [CVE-2026-0247] Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247 Prisma Access Agent Endpoint DLP: Authorization Bypass Vulnerabilities

CVE-2026-0247
Prisma Access
May 13, 2026
High7.8Fortinet Exploited CISA KEV

High [CVE-2026-31431] Linux Kernel Vulnerability - CVE-2026-31431

CVSSv3 Score: 7.8 CVE-2026-31431 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. Revised on 2026-05-13 00:00:00

CVE-2026-31431
Unclassified
May 13, 2026
High7.0NetApp

High [CVE-2024-36899] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.7-rc1 through 6.6.30, 6.7-rc1 through 6.8.9 and 6.9-rc1 through 6.9-rc7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-36899
Unclassified
May 13, 2026
High7.8NetApp

High [CVE-2026-43500] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.3-rc7 through 6.18.28, 6.19-rc1 through 7.0.5 and 7.1-rc1 through 7.1-rc2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). This CVE is part of the Dirty Frag vulnerability class. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-43500
Unclassified
May 13, 2026
High7.2Aruba

High [CVE-2026-44871] AOS-10: Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44871
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44872] AOS-10: command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems

A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to place arbitrary files on the underlying filesystem of the affected device. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44872
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44869] AOS-10: Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44869
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44864] AOS-10: SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol

SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 command-line interface and management protocol. An authenticated attacker with administrative privileges could exploit these vulnerabilities by injecting crafted input into parameters that are passed unsanitized to backend database queries. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system.

CVE-2026-44864
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44859] AOS-10: Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems

Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these vulnerabilities by sending specially crafted requests to the affected services. Successful exploitation could allow the attacker to execute arbitrary code with elevated privileges on the underlying operating system.

CVE-2026-44859
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-44854] AOS-10: Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems

Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote code execution as a privileged user. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44854
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.2Aruba Updated

High [CVE-2026-44852] AOS-10: authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface

An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating system by exploiting improper input validation in the file path parameter. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system as a privileged user. Affected products named by the advisory: AOS-8 Mobility.

CVE-2026-44852
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.5Aruba

High [CVE-2026-23827] AOS-10: heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution

A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow an unauthenticated remote attacker to achieve remote code execution. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code as a privileged user on the underlying operating system, potentially leading to a system compromise. Exploitation may also result in a denial-of-service (DoS) condition affecting the impacted system process.

CVE-2026-23827
AOS-10AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.5Aruba

High [CVE-2026-23826] AOS-8: vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition

A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker to exploit this vulnerability by sending specially crafted network packets to the affected device, potentially resulting in a denial-of-service condition. Successful exploitation could cause the affected service process to terminate unexpectedly, disrupting normal device operations.

CVE-2026-23826
AOS-8 MobilityWireless & ControllersArubaOS
May 12, 2026
High7.5Aruba Updated

High [CVE-2026-23825] AOS-10: Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems

Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network messages to the affected service. Due to insufficient input validation, successful exploitation may terminate a critical system process, resulting in a denial-of-service condition.

CVE-2026-23825
AOS-10Wireless & ControllersArubaOS
May 12, 2026
High7.2Aruba

High [CVE-2026-23823] AOS-10: vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection

A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attacker to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. NOTE: This vulnerability only impacts Access Points running AOS-10.7.x.x and above. AOS-10.4 AP and AOS-8 Instant software branches are not affected by this vulnerability.

CVE-2026-23823
AOS-10AOS-8 MobilityWireless & ControllersInstant
May 12, 2026
High7.2Aruba

High [CVE-2026-23821] AOS-10: vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions

A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system. Note: Access Points running AOS-8 Instant software are not affected by this vulnerability.

CVE-2026-23821
AOS-10AOS-8 MobilityWireless & ControllersInstant
May 12, 2026