Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-70906

CVE-2026-70906: 2 tracked advisory records across NetApp, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

NetApp

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-70906] Java SE Vulnerability in NetApp Products

    NTAP-20260821-0008Source published Source updated

    Java SE versions 25.0.4 and 26.0.2 are susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details.

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-70906] Improve font loading (2026-08 Security Update)

    CVE-2026-70906Source published Source updated

    Vulnerability in Oracle Java SE (component: 2D). Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Red Hat severity: Moderate — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Exploit Intelligence; Red Hat…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat Hardened Images
    • Exploit Intelligence

    5 more entries in the full advisory.

    Source-reported affected versions
    • 25.0.4
    • 26.0.2
    Source-reported fixed versions
    • java-25-openjdk-1:25.0.4.1.1-1.1.el10
    • java-25-openjdk-1:25.0.4.1.1-1.1.el9
    • java-25-openjdk-portable-main-25.0.4.1.1-0.1.hum1
    • java-25-openjdk-main-25.0.4.1.1-1.1.hum1

    3 more entries in the full advisory.

    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery