Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical10.0NetApp

Critical [CVE-2026-4480] Samba Vulnerability in NetApp Products

Samba versions prior to 4.22.10, 4.23.8 and 4.24.3 are susceptible to a vulnerability which when successfully exploited could lead to unauthenticated Remote Code Execution. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-4480
Unclassified
May 27, 2026
Critical9.2NetApp

Critical [CVE-2026-42945] NGINX Vulnerability in NetApp Products

Multiple NetApp products incorporate NGINX. NGINX versions 0.6.27 through 0.9.7 and 1.0.0 through 1.30.0 are susceptible to a vulnerability referred to as NGINX Rift which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-42945
Unclassified
May 22, 2026
High7.8NetApp

High [CVE-2026-46300] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a local privilege escalation vulnerability referred to as Fragnesia that could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-46300
Unclassified
May 22, 2026
High7.5NetApp

High [CVE-2026-6276] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.71.0 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6276
AFF / ASA / FASElement Software
May 15, 2026
High7.5NetApp

High [CVE-2026-5773] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.40.0 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5773
AFF / ASA / FASElement Software
May 15, 2026
High7.5NetApp

High [CVE-2026-6429] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.14.0 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6429
AFF / ASA / FASElement Software
May 15, 2026
High7.0NetApp

High [CVE-2024-36899] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.7-rc1 through 6.6.30, 6.7-rc1 through 6.8.9 and 6.9-rc1 through 6.9-rc7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-36899
Unclassified
May 13, 2026
High7.8NetApp

High [CVE-2026-43500] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.3-rc7 through 6.18.28, 6.19-rc1 through 7.0.5 and 7.1-rc1 through 7.1-rc2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). This CVE is part of the Dirty Frag vulnerability class. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-43500
Unclassified
May 13, 2026
Critical9.8NetApp

Critical [CVE-2026-22984] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions through 5.15.197, 5.16-rc1 through 6.1.160, 6.13-rc1 through 6.18.5, 6.19-rc1 through 6.19-rc4, 6.2-rc1 through 6.6.120 and 6.7-rc1 through 6.12.65 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22984
Unclassified
May 8, 2026
Critical9.8NetApp

Critical [CVE-2026-28780] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-28780
Unclassified
May 8, 2026
High8.3NetApp

High [CVE-2026-0603] Hibernate ORM Vulnerability in NetApp Products

Multiple NetApp products incorporate Hibernate ORM. Hibernate ORM versions 5.2.8 through 5.6.15 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-0603
Active IQ Unified ManagerONTAP tools for VMware
May 8, 2026
High7.5NetApp

High [CVE-2026-27137] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions 1.26.0-0 prior to 1.26.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). Affected products: Astra Control Center, Astra Control Center - NetApp Kubernetes Monitoring Operator, Data Infrastructure Insights Telegraf Agent, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-27137
Trident / AstraONTAP tools for VMwareOnCommand / Data Infrastructure InsightsNetApp tools & integrations
May 8, 2026
High7.5NetApp

High [CVE-2026-22992] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux Kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22992
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerONTAP tools for VMware
May 8, 2026
High7.5NetApp

High [CVE-2026-23003] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.10.210 through 5.14.21, 5.15.149 through 5.15.198, 6.13-rc1 through 6.18.6, 6.19-rc1 through 6.19-rc5, 6.6.16 through 6.6.121, 6.7.4 through 6.7.12 and 6.8-rc3 through 6.12.66 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-23003
Unclassified
May 8, 2026
High7.5NetApp

High [CVE-2026-29169] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-29169
Unclassified
May 8, 2026
High7.5NetApp Updated

High [CVE-2026-22990] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions through 5.10.247, 5.11-rc1 through 5.15.197, 5.16-rc1 through 6.1.160, 6.13-rc1 through 6.18.5, 6.19-rc1 through 6.19-rc4, 6.2-rc1 through 6.6.120 and 6.7-rc1 through 6.12.65 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22990
ONTAP tools for VMware
May 8, 2026
High7.5NetApp

High [CVE-2026-22997] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.4-rc1 through 6.12.66, 6.13-rc1 through 6.18.6 and 6.19-rc1 through 6.19-rc5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22997
Unclassified
May 8, 2026
High7.5NetApp

High [CVE-2026-34059] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp states there is no workaround available at this time.

CVE-2026-34059
Unclassified
May 8, 2026
High7.3NetApp

High [CVE-2026-29168] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions 2.4.30 through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-29168
Unclassified
May 8, 2026
High8.8NetApp

High [CVE-2026-23918] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server version 2.4.66 is susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-23918
Unclassified
May 8, 2026