Home / Security / CVE index / 2026
2026 NetApp CVEs (page 4)
Showing 95 CVEs with a 2026 identifier — page 4 of 4. Sorted by CVE id.
Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 95 of 95
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-2026-63263 | — | — | — | NVD ↗ · NTAP-20260807-0019 |
CVE-2026-63687 | — | — | — | NVD ↗ · NTAP-20260911-0004 |
CVE-2026-6386 | — | — | — | NVD ↗ · NTAP-20260429-0014 |
CVE-2026-6429 | — | — | — | NVD ↗ · NTAP-20260515-0003 |
CVE-2026-64319 | — | — | — | NVD ↗ · NTAP-20260814-0005 |
CVE-2026-64391 | — | — | — | NVD ↗ · NTAP-20260814-0002 |
CVE-2026-64531 | — | — | — | NVD ↗ · NTAP-20260807-0005 |
CVE-2026-64534 | — | — | — | NVD ↗ · NTAP-20260814-0003 |
CVE-2026-64535 | — | — | — | NVD ↗ · NTAP-20260814-0004 |
CVE-2026-6471 | — | — | — | NVD ↗ · NTAP-20260911-0017 |
CVE-2026-64958 | — | — | — | NVD ↗ · NTAP-20260911-0010 |
CVE-2026-65182 | — | — | — | NVD ↗ · NTAP-20260902-0012 |
CVE-2026-65183 | — | — | — | NVD ↗ · NTAP-20260902-0014 |
CVE-2026-65432 | — | — | — | NVD ↗ · NTAP-20260911-0011 |
CVE-2026-65583 | — | — | — | NVD ↗ · NTAP-20260911-0005 |
CVE-2026-65637 | — | — | — | NVD ↗ · NTAP-20260902-0010 |
CVE-2026-65905 | — | — | — | NVD ↗ · NTAP-20260902-0011 |
CVE-2026-65927 | — | — | — | NVD ↗ · NTAP-20260902-0017 |
CVE-2026-66032 | 2026-07-24 | HIGH | 8.8 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH serv NVD ↗ · NTAP-20260807-0001 |
CVE-2026-66033 | 2026-07-24 | HIGH | 7.5 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openss NVD ↗ · NTAP-20260807-0002 |
CVE-2026-66034 | — | — | — | NVD ↗ · NTAP-20260807-0003 |
CVE-2026-66035 | — | — | — | NVD ↗ · NTAP-20260807-0004 |
CVE-2026-66299 | — | — | — | NVD ↗ · NTAP-20260902-0018 |
CVE-2026-66422 | — | — | — | NVD ↗ · NTAP-20260902-0015 |
CVE-2026-6653 | — | — | — | NVD ↗ · NTAP-20260717-0020 |
CVE-2026-66909 | — | — | — | NVD ↗ · NTAP-20260911-0001 |
CVE-2026-6726 | — | — | — | NVD ↗ · NTAP-20260821-0013 |
CVE-2026-6727 | — | — | — | NVD ↗ · NTAP-20260821-0014 |
CVE-2026-67593 | 2026-09-10 | CRITICAL | 9.1 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authenticati NVD ↗ · NTAP-20260925-0001 |
CVE-2026-68079 | — | — | — | NVD ↗ · NTAP-20260911-0002 |
CVE-2026-68481 | — | — | — | NVD ↗ · NTAP-20260911-0012 |
CVE-2026-68494 | 2026-08-04 | HIGH | 8.7 | The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incom NVD ↗ · NTAP-20260930-0001 |
CVE-2026-68525 | — | — | — | NVD ↗ · NTAP-20260902-0013 |
CVE-2026-68569 | — | — | — | NVD ↗ · NTAP-20260902-0016 |
CVE-2026-68763 | — | — | — | NVD ↗ · NTAP-20260902-0019 |
CVE-2026-6918 | 2026-05-05 | HIGH | 7.5 | In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. NVD ↗ · NTAP-20260917-0001 |
CVE-2026-6938 | — | — | — | NVD ↗ · NTAP-20260529-0009 |
CVE-2026-6949 | — | — | — | NVD ↗ · NTAP-20260821-0020 |
CVE-2026-7009 | — | — | — | NVD ↗ · NTAP-20260515-0007 |
CVE-2026-70906 | — | — | — | NVD ↗ · NTAP-20260821-0008 |
CVE-2026-70907 | — | — | — | NVD ↗ · NTAP-20260821-0009 |
CVE-2026-71073 | — | — | — | NVD ↗ · NTAP-20260821-0007 |
CVE-2026-71079 | — | — | — | NVD ↗ · NTAP-20260821-0007 |
CVE-2026-71084 | — | — | — | NVD ↗ · NTAP-20260821-0007 |
CVE-2026-7164 | — | — | — | NVD ↗ · NTAP-20260501-0007 |
CVE-2026-7168 | — | — | — | NVD ↗ · NTAP-20260515-0008 |
CVE-2026-72522 | 2026-08-10 | MEDIUM | 6.2 | libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode proces NVD ↗ · NTAP-20260924-0021 |
CVE-2026-7270 | — | — | — | NVD ↗ · NTAP-20260501-0003 |
CVE-2026-73180 | — | — | — | NVD ↗ · NTAP-20260902-0020 |
CVE-2026-73281 | — | — | — | NVD ↗ · NTAP-20260821-0010 |
CVE-2026-73282 | — | — | — | NVD ↗ · NTAP-20260821-0011 |
CVE-2026-73283 | — | — | — | NVD ↗ · NTAP-20260821-0012 |
CVE-2026-73581 | 2026-09-23 | MEDIUM | 6.5 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses NVD ↗ · NTAP-20261002-0011 |
CVE-2026-7383 | 2026-06-09 | HIGH | 8.1 | Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impa NVD ↗ · NTAP-20260617-0003 |
CVE-2026-75029 | 2026-09-16 | MEDIUM | 5.3 | In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on a NVD ↗ · NTAP-20260930-0016 |
CVE-2026-75803 | — | — | — | NVD ↗ · NTAP-20260902-0002 |
CVE-2026-75973 | 2026-09-23 | HIGH | 7.3 | Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and mul NVD ↗ · NTAP-20261002-0010 |
CVE-2026-7598 | 2026-05-01 | HIGH | 7.3 | A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such mani NVD ↗ · NTAP-20260814-0020 |
CVE-2026-76163 | 2026-09-16 | HIGH | 7.5 | If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion NVD ↗ · NTAP-20260930-0005 |
CVE-2026-76183 | 2026-09-23 | CRITICAL | 9.8 | Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue af NVD ↗ · NTAP-20261002-0002 |
CVE-2026-76957 | 2026-08-20 | MEDIUM | 4.9 | libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-5021 NVD ↗ · NTAP-20260924-0025 |
CVE-2026-77119 | 2026-09-16 | MEDIUM | 5.9 | A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answ NVD ↗ · NTAP-20260930-0013 |
CVE-2026-77692 | 2026-09-16 | HIGH | 7.5 | An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transpor NVD ↗ · NTAP-20260930-0006 |
CVE-2026-7771 | — | — | — | NVD ↗ · NTAP-20260717-0006 |
CVE-2026-77756 | 2026-09-23 | LOW | 3.7 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding heade NVD ↗ · NTAP-20261002-0012 |
CVE-2026-77762 | 2026-09-23 | HIGH | 8.1 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer NVD ↗ · NTAP-20261002-0004 |
CVE-2026-77791 | 2026-09-23 | HIGH | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomca NVD ↗ · NTAP-20261002-0008 |
CVE-2026-78301 | 2026-09-16 | MEDIUM | 5.8 | A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND autho NVD ↗ · NTAP-20260930-0014 |
CVE-2026-78383 | 2026-09-23 | HIGH | 7.5 | Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leadin NVD ↗ · NTAP-20261002-0007 |
CVE-2026-78437 | 2026-09-23 | HIGH | 7.3 | Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. Thi NVD ↗ · NTAP-20261002-0009 |
CVE-2026-7884 | 2026-09-14 | MEDIUM | 5.4 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malic NVD ↗ · NTAP-20260917-0001 |
CVE-2026-79677 | 2026-09-23 | HIGH | 7.5 | Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lo NVD ↗ · NTAP-20261002-0006 |
CVE-2026-80274 | 2026-09-16 | HIGH | 7.5 | If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proo NVD ↗ · NTAP-20260930-0007 |
CVE-2026-81563 | 2026-09-16 | HIGH | 7.5 | A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resou NVD ↗ · NTAP-20260930-0008 |
CVE-2026-81736 | 2026-09-16 | HIGH | 7.5 | If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CP NVD ↗ · NTAP-20260930-0009 |
CVE-2026-84445 | — | — | — | NVD ↗ · NTAP-20260917-0012 |
CVE-2026-86087 | 2026-09-10 | MEDIUM | 4.3 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the s NVD ↗ · NTAP-20260917-0011 |
CVE-2026-86093 | 2026-09-10 | HIGH | 7.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute ar NVD ↗ · NTAP-20260917-0007 |
CVE-2026-86248 | 2026-09-23 | CRITICAL | 9.8 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tom NVD ↗ · NTAP-20261002-0001 |
CVE-2026-86350 | 2026-09-23 | CRITICAL | 9.1 | Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-412 NVD ↗ · NTAP-20261002-0003 |
CVE-2026-87022 | 2026-09-23 | HIGH | 7.5 | Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This iss NVD ↗ · NTAP-20261002-0005 |
CVE-2026-87958 | 2026-09-10 | HIGH | 8.1 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by NVD ↗ · NTAP-20260917-0004 |
CVE-2026-8924 | — | — | — | NVD ↗ · NTAP-20260731-0006 |
CVE-2026-8925 | — | — | — | NVD ↗ · NTAP-20260731-0003 |
CVE-2026-8926 | — | — | — | NVD ↗ · NTAP-20260731-0007 |
CVE-2026-8927 | — | — | — | NVD ↗ · NTAP-20260731-0008 |
CVE-2026-89662 | 2026-09-11 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock owner use-after-free during client teardown __destroy_client() releases a NVD ↗ · NTAP-20261002-0013 |
CVE-2026-89669 | 2026-09-11 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publishing it nfsd4_copy_notify() finished initi NVD ↗ · NTAP-20261002-0014 |
CVE-2026-89674 | 2026-09-11 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget The XDR buffer size calculatio NVD ↗ · NTAP-20261002-0015 |
CVE-2026-89712 | 2026-09-11 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() NVD ↗ · NTAP-20261002-0016 |
CVE-2026-9076 | 2026-06-09 | HIGH | 7.5 | Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher c NVD ↗ · NTAP-20260617-0008 |
CVE-2026-9079 | — | — | — | NVD ↗ · NTAP-20260731-0004 |
CVE-2026-9256 | — | — | — | NVD ↗ · NTAP-20260605-0012 |
CVE-2026-9762 | — | — | — | NVD ↗ · NTAP-20260717-0003 |
CVE-2026-9828 | — | — | — | NVD ↗ · NTAP-20260731-0012 |
Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999