Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.8F5

High [CVE-2026-27784] NGINX ngx_http_mp4_module vulnerability

The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27784
NGINX
Mar 24, 2026
High8.2F5

High [CVE-2026-27654] NGINX ngx_http_dav_module vulnerability

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configuration file uses DAV module MOVE or COPY methods, prefix location (nonregular expression location configuration), and alias directives. The integrity impact is constrained because the NGINX worker process user has low privileges and does not have access to the entire system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27654
NGINX
Mar 24, 2026
High7.5F5

High [CVE-2026-27651] NGINX ngx_mail_auth_http_module vulnerability

When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2026-27651
NGINX
Mar 24, 2026
High8.1QNAP

High [CVE-2026-22897 +3] command injection vulnerability has been reported to affect QuNetSwitch.

A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch 2.0.4.0415 and later Affected product named by the advisory: QuNetSwitch 2.0.x.

CVE-2026-22897CVE-2026-22900CVE-2026-22901+1
Unclassified
Mar 20, 2026
High7.3QNAP

High [CVE-2025-62843 +3] improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora.

An improper restriction of communication channel to intended endpoints vulnerability has been reported to affect QHora. If an attacker gains physical access, they can then exploit the vulnerability to gain the privileges that were intended for the original endpoint. We have already fixed the vulnerability in the following version: QuRouter 2.6.3.009 and later Affected product named by the advisory: QuRouter 2.6.x.

CVE-2025-62843CVE-2025-62844CVE-2025-62845+1
Unclassified
Mar 20, 2026
High7.8NetApp Updated

High [CVE-2026-23231] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-23231
Active IQ Unified ManagerONTAP tools for VMware
Mar 20, 2026
High8.1NetApp Updated

High [CVE-2026-0861] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C. GNU C Library (aka glibc) versions 2.30 through 2.42 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, NetApp HCI Baseboard Management Controller (BMC) - H610S, Trident. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-0861
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerTrident / Astra
Mar 20, 2026
High8.6Atlassian

High [CVE-2026-21570] Confluence: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0…

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bamboo Data Center 9.6: Upgrade to a release greater than or equal to 9.6.24 Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.16 Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.3 See the release notes ([ ]). This vulnerability was reported via our Atlassian (Internal) program. Affected products named by the advisory: Confluence.

CVE-2026-21570
ConfluenceBamboo / Crowd / Fisheye
Mar 17, 2026
High7.5NetApp Updated

High [CVE-2026-25639] Axios Vulnerability in NetApp Products

Multiple NetApp products incorporate Axios. Axios versions prior to 0.30.3 prior and to 1.13.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp Shift Toolkit, ONTAP tools for VMware vSphere 10, Storage Manager for ProxMox. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-25639
ONTAP tools for VMwareNetApp tools & integrations
Mar 13, 2026
HighIvanti Exploited

High March 2026 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Desktop and Server Management (DSM). It is important for customers to know: - We have no evidence of this vulnerability being exploited in the wild. - This vulnerability does not impact any other Ivanti solutions. More information on this vulnerability and detailed instructions on how to remediate the issues can be found in this Security Advisory.

Unclassified
Mar 10, 2026
High7.8NetApp Updated

High [CVE-2026-23001] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-23001
Unclassified
Mar 5, 2026
High7.0Docker

High [CVE-2025-15558] Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are executed when a victim user opens Docker Desktop or invokes Docker CLI plugin features, and allow privilege-escalation if the docker CLI is executed as a privileged user. This issue affects Docker CLI: through 29.1.5 and Windows binaries acting as a CLI-plugin manager using the github.com/docker/cli/cli-plugins/manager package, such as Docker Compose. This issue does not impact non-Windows binaries, and projects not using the plugin-manager code.

CVE-2025-15558
Docker CLI / Scout
Mar 4, 2026
High7.5NetApp

High [CVE-2022-40735] Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

The Diffie-Hellman Key Exchange Protocol is susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). E-Series SANtricity OS Controller Software: Affected only when SSH is enabled - it is disabled by default. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: Astra Control Center; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; and 2 more. Affected products named by the advisory: ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

CVE-2022-40735
AFF / ASA / FASSANtricityTrident / AstraONTAP tools for VMware
Feb 27, 2026
HighIvanti Exploited

High February 2026 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager (EPM). It is important for customers to know: - We have no evidence of this vulnerability being exploited in the wild. - This vulnerability does not impact any other Ivanti solutions. More information on this vulnerability and detailed instructions on how to remediate the issues can be found in this Security Advisory.

Endpoint Manager
Feb 10, 2026
High7.5Fortinet

High [CVE-2026-22153] LDAP authentication bypass in Agentless VPN and FSSO

CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. Revised on 2026-07-04 00:00:00

CVE-2026-22153
FortiGateFirewallFortiOS
Feb 10, 2026
High7.5NetApp Updated

High [CVE-2025-69420] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp Manageability SDK: OpenSSL was removed in 9.8P8. Affected products: Brocade SAN Navigator (SANnav), Management Services for Element Software and NetApp HCI, NetApp Console Agent Container (cbs-backend), ONTAP 9, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-69420
ONTAPElement SoftwareBlueXP / NetApp ConsoleBrocade SANnav / Fabric OS
Feb 4, 2026
High7.0WatchGuard

High [CVE-2026-1498] WatchGuard Firebox LDAP Injection

An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.

CVE-2026-1498
Firebox / Fireware
Jan 30, 2026
High7.5NetApp

High [CVE-2025-61729] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to 1.24.11 and 1.25.0 prior to 1.25.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, Data Infrastructure Insights Telegraf Agent, NetApp Console Agent, ONTAP tools for VMware vSphere 10, Trident. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-61729
BlueXP / NetApp ConsoleTrident / AstraONTAP tools for VMwareOnCommand / Data Infrastructure Insights
Jan 30, 2026
HighIvanti

High January 2026 EPMM Security Update

At Ivanti, responsible transparency is a cornerstone of our commitment to customer security and trust. We have a long-standing commitment to provide information that allows our customers and the broader security ecosystem to take proactive measures to safeguard their environments, while mitigating the risks of a rapidly evolving and highly sophisticated threat landscape. To this end, we are issuing an important security update addressing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). More information can be found in the Security Advisory. At the time of disclosure, we are aware of a very limited number of customers whose solution has been exploited. The issue affects only the on-prem EPMM product. It is not present in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint management solution, Ivanti EPM (a similarly named, but different product), Ivanti Sentry, or any other Ivanti products. We urge all customers using the on-prem EPMM product to promptly install the Security Update. As we respond to this situation, we are making the following information available to defenders now: - Our Security Advisory, which describes the nature of the vulnerabilities and detailed remediation instructions for customers. - A Technical Analysis that includes affected endpoint specifics and log analysis guidance to support investigation and forensics.

EPMM / MobileIronNeuronsEndpoint ManagerSentry
Jan 29, 2026
High7.5NetApp

High [CVE-2026-21925 +3] January 2026 Java Platform Standard Edition Vulnerabilities in NetApp Products

Multiple NetApp products incorporate the Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1 are susceptible to vulnerabilities that could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data as well as unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data, and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. OnCommand Insight: Affected by only CVE-2026-21925 and CVE-2026-21933. Data Infrastructure Insights Storage Workload Security Agent: NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights and Data Secure Storage Workload Security Agent; NetApp Console Agent.

CVE-2026-21925CVE-2026-21932CVE-2026-21933+1
Active IQ Unified ManagerBlueXP / NetApp ConsoleOnCommand / Data Infrastructure Insights
Jan 23, 2026