Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.7NetApp

Medium [CVE-2026-27456] Util-linux Vulnerability in NetApp Products

Multiple NetApp products incorporate util-linux. Util-linux versions prior to 2.41.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-27456
Active IQ Unified Manager
Jun 12, 2026
Low3.7NetApp

Low [CVE-2026-3184] Util-linux Vulnerability in NetApp Products

Multiple NetApp products incorporate util-linux. Util-linux versions through 2.42 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-3184
Active IQ Unified Manager
Jun 12, 2026
High8.7NetApp

High [CVE-2026-49975] Apache HTTP Server Vulnerability in NetApp Products

The default HTTP/2 protocol configuration in certain web servers, such as Apache HTTP Server, allows a remote Denial of Service (DoS). This vulnerability is known as HTTP/2 Bomb. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Management Services for Element Software and NetApp HCI. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-49975
Element Software
Jun 10, 2026
Critical9.8NetApp

Critical [CVE-2026-43501] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.7-rc1 through 6.6.139, 6.13-rc1 through 6.18.26, 6.19-rc1 through 7.0.3, 6.7-rc1 through 6.12.85, and 7.1-rc1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-43501
Unclassified
Jun 5, 2026
Critical9.8NetApp

Critical [CVE-2026-31607] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31607
Unclassified
Jun 5, 2026
High7.5NetApp

High [CVE-2026-40972 +3] April 2026 Spring Boot Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Spring Boot. Spring Boot versions 4.0.0 through 4.0.5, 3.5.0 through 3.5.13, 3.4.0 through 3.4.15, 3.3.0 through 3.3.18, and 2.7.0 through 2.7.32 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). OnCommand Insight: Affected only by CVE-2026-40975. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-40972CVE-2026-40973CVE-2026-40974+1
OnCommand / Data Infrastructure Insights
Jun 5, 2026
High8.7NetApp

High [CVE-2026-35554] Apache Kafka Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Kafka. Apache Kafka versions 2.8.0 through 3.9.1, 4.0.0 through 4.0.1, and 4.1.0 through 4.1.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-35554
Unclassified
Jun 5, 2026
High8.1NetApp

High [CVE-2026-9256] NGINX Vulnerability in NetApp Products

Multiple NetApp products incorporate NGINX. NGINX versions prior to 1.30.2 and 1.31.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-9256
Unclassified
Jun 5, 2026
Critical9.8NetApp

Critical [CVE-2025-48431 +10] April 2026 Apache Thrift Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Thrift. Apache Thrift versions prior to 0.23.0 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-48431CVE-2026-41602CVE-2026-41603+8
Unclassified
May 29, 2026
High7.3NetApp

High [CVE-2026-41284 +5] May 2026 Apache Tomcat Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Apache Tomcat. Apache Tomcat versions 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, and 9.0.0.M1 through 9.0.117 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-41284CVE-2026-41293CVE-2026-43512+3
Unclassified
May 29, 2026
High7.4NetApp

High [CVE-2026-3593] ISC BIND Vulnerability in NetApp Products

Multiple NetApp products incorporate ISC BIND. ISC BIND versions 9.20.0 through 9.20.22 and 9.21.0 through 9.21.21 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-3593
Unclassified
May 29, 2026
High7.5NetApp

High [CVE-2026-5947] ISC BIND Vulnerability in NetApp Products

Multiple NetApp products incorporate ISC BIND. ISC BIND versions 9.20.0 through 9.20.22 and 9.21.0 through 9.21.21 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5947
Unclassified
May 29, 2026
Critical10.0NetApp

Critical [CVE-2026-4480] Samba Vulnerability in NetApp Products

Samba versions prior to 4.22.10, 4.23.8 and 4.24.3 are susceptible to a vulnerability which when successfully exploited could lead to unauthenticated Remote Code Execution. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-4480
Unclassified
May 27, 2026
Critical9.2NetApp

Critical [CVE-2026-42945] NGINX Vulnerability in NetApp Products

Multiple NetApp products incorporate NGINX. NGINX versions 0.6.27 through 0.9.7 and 1.0.0 through 1.30.0 are susceptible to a vulnerability referred to as NGINX Rift which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-42945
Unclassified
May 22, 2026
High7.8NetApp

High [CVE-2026-46300] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a local privilege escalation vulnerability referred to as Fragnesia that could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-46300
Unclassified
May 22, 2026
High7.5NetApp

High [CVE-2026-6429] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.14.0 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6429
AFF / ASA / FASElement Software
May 15, 2026
Low3.7NetApp

Low [CVE-2026-2391] Qs Vulnerability in NetApp Products

Multiple NetApp products incorporate qs. Qs versions 6.7.0 through 6.14.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-2391
Unclassified
May 15, 2026
High7.0NetApp

High [CVE-2024-36899] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.7-rc1 through 6.6.30, 6.7-rc1 through 6.8.9 and 6.9-rc1 through 6.9-rc7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-36899
Unclassified
May 13, 2026
High7.8NetApp

High [CVE-2026-43500] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Linux kernel versions 5.3-rc7 through 6.18.28, 6.19-rc1 through 7.0.5 and 7.1-rc1 through 7.1-rc2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). This CVE is part of the Dirty Frag vulnerability class. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-43500
Unclassified
May 13, 2026
Medium6.3NetApp

Medium [CVE-2026-34477] Apache Log4j Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Log4j. Apache Log4j versions 2.12.0 through 2.25.3 and 3.0.0-alpha1 through 3.0.0-beta3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-34477
Unclassified
May 13, 2026