Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

43 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.7NetApp

High [CVE-2026-59874] Tar Vulnerability in NetApp Products

Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59874
Unclassified
Aug 28, 2026
High7.8NetApp

High [CVE-2026-49429 +2] June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-49429CVE-2026-49430CVE-2026-49431
Unclassified
Aug 28, 2026
High7.1NetApp

High [CVE-2026-17106] Docker Engine Vulnerability in NetApp Products

Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-17106
Unclassified
Aug 28, 2026
High8.4NetApp

High [CVE-2026-44604 +1] Attr Vulnerability in NetApp Products

Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44604CVE-2026-54371
Unclassified
Aug 28, 2026
High7.3NetApp

High [CVE-2026-15571] Keycloak Vulnerability in NetApp Products

Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-15571
Unclassified
Aug 28, 2026
High7.0NetApp

High [CVE-2026-44604] RPM Vulnerability in NetApp Products

RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-44604
Unclassified
Aug 28, 2026
High8.1NetApp

High [CVE-2026-54513] FasterXML Jackson Databind Vulnerability in NetApp Products

FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-54513
Unclassified
Aug 28, 2026
High7.2NetApp

High [CVE-2026-54370] Acl Vulnerability in NetApp Products

Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-54370
Unclassified
Aug 28, 2026
High8.3NetApp

High [CVE-2026-59250] Erlang/OTP Vulnerability in NetApp Products

Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-59250
Unclassified
Aug 28, 2026
High8.8NetApp Updated

High [CVE-2026-58222] Samba Vulnerability in NetApp Products

Samba Active Directory Domain Controller versions 4.0.0 and higher are susceptible to a vulnerability which when successfully exploited permits an ordinary authenticated domain user to bypass access checks and query confidential Active Directory attributes (such as KDS root keys) via LDAP Compare requests. Due to a filter injection flaw and trusted execution context, the LDAP Compare operation can be turned into a protected-attribute disclosure oracle. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-58222
Unclassified
Aug 21, 2026
High8.5NetApp Updated

High [CVE-2026-6726] Trusted Platform Module 2.0 Vulnerability in NetApp Products

The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which when exploited could allow improper reuse of object slots between key/data objects and hash contexts, enabling an attacker to falsify TPM attestations and credentials. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-6726
Unclassified
Aug 21, 2026
High7.5NetApp

High [CVE-2026-70906] Java SE Vulnerability in NetApp Products

Java SE versions 25.0.4 and 26.0.2 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-70906
Unclassified
Aug 21, 2026
High7.1NetApp

High [CVE-2026-58224] Samba Vulnerability in NetApp Products

Samba versions 4.2 and higher are susceptible to a vulnerability which when successfully exploited could result in Denial of Service (DoS) and possible limited disclosure of adjacent memory allocations. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-58224
Unclassified
Aug 21, 2026
High8.3NetApp Updated

High [CVE-2026-6727] Trusted Platform Module 2.0 Vulnerability in NetApp Products

The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which exposes a timing side-channel in RSA OAEP decryption, enabling an attacker to decrypt sensitive blobs (import blobs, credential blobs, and session salts) encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), or to falsify TPM 2.0 Attestation Keys. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-6727
Unclassified
Aug 21, 2026
High8.7NetApp

High [CVE-2026-29036] cJSON Vulnerability in NetApp Products

cJSON versions 1.5.0 through 1.7.19 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-29036
Unclassified
Aug 21, 2026
High7.5NetApp

High [CVE-2026-6949] Samba Vulnerability in NetApp Products

Samba versions 4.0 and higher are susceptible to a vulnerability which when successfully exploited could lead to a large out-of-bounds write causing the server to crash. Successful exploitation of this vulnerability could lead to addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6949
Unclassified
Aug 21, 2026
High8.8NetApp

High [CVE-2026-58221] Samba Vulnerability in NetApp Products

Samba AD DC versions 4.0.0 and higher are susceptible to a vulnerability which when successfully exploited permits a domain takeover by allowing low-privilege authenticated LDAP access modifications to internal LDB special DNs. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-58221
Unclassified
Aug 21, 2026
High7.5NetApp Updated

High [CVE-2026-14456] OpenSSL Vulnerability in NetApp Products

OpenSSL versions 4.0, 3.6, and 3.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-14456
Unclassified
Aug 21, 2026
High7.5NetApp

High [CVE-2026-58043] Node.js Vulnerability in NetApp Products

Node.js versions 22.x through 22.23.1, 24.x through 24.18.0, and 26.x through 26.5.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-58043
Unclassified
Aug 21, 2026
High8.7NetApp

High [CVE-2025-20005 +8] Intel SA-01234 UEFI Vulnerabilities in NetApp Products

Potential security vulnerabilities in UEFI for some Intel reference platforms may allow escalation of privilege or information disclosure. Intel is releasing UEFI firmware updates to mitigate these potential vulnerabilities. Refer to the vendor advisory INTEL-SA-01234 for specific version details. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-20005CVE-2025-20027CVE-2025-20028+6
Unclassified
Aug 14, 2026