Skip to content
VulniPulse
Highest advisory severityMedium 2 vendors · 2 advisories

CVE-2026-40977

CVE-2026-40977: 2 tracked advisory records across NetApp, VMware. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

NetApp

1 advisory
  • Advisory severityMedium4.7

    Medium [CVE-2026-40977] Spring Boot Vulnerability in NetApp Products

    NTAP-20260605-0009Source published Source updated

    Multiple NetApp products incorporate Spring Boot. Certain versions of Spring Boot are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: Data Infrastructure Insights and Data Secure Storage Workload Security Agent. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

    Affected products in this advisory
    • Data Infrastructure Insights and Data Secure Storage Workload Security Agent
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • Data Infrastructure Insights and Data Secure Storage Workload Security Agent: Fixed as of 20260803.

VMware

1 advisory
  • Advisory severityMedium4.7

    Medium [CVE-2026-40977] Spring Boot: When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location

    CVE-2026-40977Source published Source updated

    When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.

    Related products — impact not confirmed
    • Spring Boot
    Source-reported affected versions
    • 4.0.0
    • 4.0.5
    • 4.0.6
    • 3.5.0

    11 more entries in the full advisory.

    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery