CVE-2026-21937
CVE-2026-21937: 2 tracked advisory records across NetApp, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
NetApp
1 advisory- Advisory severityHigh7.5
High [CVE-2025-9230 +6] January 2026 MySQL Server Vulnerabilities in NetApp Products
NTAP-20260123-0009Source published Source updated
This bulletin covers 7 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
Multiple NetApp products incorporate MySQL. MySQL versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7, and 9.0.0 through 9.5.0 are susceptible to a vulnerability that could allow unauthenticated, high and low privileged attackers with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight, SnapCenter.
- Affected products in this advisory
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- OnCommand Insight
- SnapCenter
- Source-reported affected versions
- 8.0.0
- 8.0.44
- 8.4.0
- 8.4.7
2 more entries in the full advisory.
- Source-reported fixed versions
- Active IQ Unified Manager for Microsoft Windows: 9.18P3
- Active IQ Unified Manager for VMware vSphere: 9.18P3
- SnapCenter: 6.2.1
- Mitigation guidance
- Update affected NetApp products to a fixed release: Active IQ Unified Manager for Microsoft Windows: 9.18P3, Active IQ Unified Manager for VMware vSphere: 9.18P3, SnapCenter: 6.2.1.
- Workarounds
- Full Support versions of SnapCenter Server allow MySQL software to be upgraded within documented constraints. Consult the product documentation for supported MySQL versions and other information related to the upgrade. <br><br> In Full Support versions of OnCommand Insight the MySQL software can be upgraded after acquiring updated OnCommand Insight binaries via technical support.
Red Hat
1 advisory- Advisory severityMedium4.9
Medium [CVE-2026-21937] DDL unspecified vulnerability (CPU Jan 2026)
CVE-2026-21937Source published
DDL unspecified vulnerability (CPU Jan 2026). Red Hat rates this moderate (CVSS 4.9). Affected package(s): mysql8.4, mysql:8.0, mysql, mysql:8.4. Resolved in Red Hat advisory RHSA-2026:5580 — update the affected packages (`sudo dnf update`).
- Related products — impact not confirmed
- Red Hat Enterprise Linux 1
- Red Hat Enterprise Linux 9
- mysql8.4
- mysql:8.0
1 more entries in the full advisory.
- Source-reported affected versions
- mysql8.4-0:8.4.8-1.el10_1
- mysql:8.0-8100020260223150324.489197e6
- mysql-0:8.0.45-1.el9_7
- mysql:8.4-8100020260219114250.489197e6
1 more entries in the full advisory.
- Source-reported fixed versions
- RHSA-2026:5580
- Mitigation guidance
- Update the affected package(s) to the fixed version shipped in RHSA-2026:5580 (`sudo dnf update` / `yum update`).
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.