Home / Security / CVE index / 2026

2026 NetApp CVEs (page 4)

Showing 95 CVEs with a 2026 identifier — page 4 of 4. Sorted by CVE id.

Always verify. NetApp's advisory is authoritative for affected versions and fixes; NVD carries the CVSS record.
Showing 95 of 95
CVEPublishedSeverityCVSSSummary / Sources
CVE-2026-63263——— NVD ↗ · NTAP-20260807-0019
CVE-2026-63687——— NVD ↗ · NTAP-20260911-0004
CVE-2026-6386——— NVD ↗ · NTAP-20260429-0014
CVE-2026-6429——— NVD ↗ · NTAP-20260515-0003
CVE-2026-64319——— NVD ↗ · NTAP-20260814-0005
CVE-2026-64391——— NVD ↗ · NTAP-20260814-0002
CVE-2026-64531——— NVD ↗ · NTAP-20260807-0005
CVE-2026-64534——— NVD ↗ · NTAP-20260814-0003
CVE-2026-64535——— NVD ↗ · NTAP-20260814-0004
CVE-2026-6471——— NVD ↗ · NTAP-20260911-0017
CVE-2026-64958——— NVD ↗ · NTAP-20260911-0010
CVE-2026-65182——— NVD ↗ · NTAP-20260902-0012
CVE-2026-65183——— NVD ↗ · NTAP-20260902-0014
CVE-2026-65432——— NVD ↗ · NTAP-20260911-0011
CVE-2026-65583——— NVD ↗ · NTAP-20260911-0005
CVE-2026-65637——— NVD ↗ · NTAP-20260902-0010
CVE-2026-65905——— NVD ↗ · NTAP-20260902-0011
CVE-2026-65927——— NVD ↗ · NTAP-20260902-0017
CVE-2026-660322026-07-24HIGH8.8libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH serv NVD ↗ · NTAP-20260807-0001
CVE-2026-660332026-07-24HIGH7.5libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openss NVD ↗ · NTAP-20260807-0002
CVE-2026-66034——— NVD ↗ · NTAP-20260807-0003
CVE-2026-66035——— NVD ↗ · NTAP-20260807-0004
CVE-2026-66299——— NVD ↗ · NTAP-20260902-0018
CVE-2026-66422——— NVD ↗ · NTAP-20260902-0015
CVE-2026-6653——— NVD ↗ · NTAP-20260717-0020
CVE-2026-66909——— NVD ↗ · NTAP-20260911-0001
CVE-2026-6726——— NVD ↗ · NTAP-20260821-0013
CVE-2026-6727——— NVD ↗ · NTAP-20260821-0014
CVE-2026-675932026-09-10CRITICAL9.1A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authenticati NVD ↗ · NTAP-20260925-0001
CVE-2026-68079——— NVD ↗ · NTAP-20260911-0002
CVE-2026-68481——— NVD ↗ · NTAP-20260911-0012
CVE-2026-684942026-08-04HIGH8.7The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incom NVD ↗ · NTAP-20260930-0001
CVE-2026-68525——— NVD ↗ · NTAP-20260902-0013
CVE-2026-68569——— NVD ↗ · NTAP-20260902-0016
CVE-2026-68763——— NVD ↗ · NTAP-20260902-0019
CVE-2026-69182026-05-05HIGH7.5In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. NVD ↗ · NTAP-20260917-0001
CVE-2026-6938——— NVD ↗ · NTAP-20260529-0009
CVE-2026-6949——— NVD ↗ · NTAP-20260821-0020
CVE-2026-7009——— NVD ↗ · NTAP-20260515-0007
CVE-2026-70906——— NVD ↗ · NTAP-20260821-0008
CVE-2026-70907——— NVD ↗ · NTAP-20260821-0009
CVE-2026-71073——— NVD ↗ · NTAP-20260821-0007
CVE-2026-71079——— NVD ↗ · NTAP-20260821-0007
CVE-2026-71084——— NVD ↗ · NTAP-20260821-0007
CVE-2026-7164——— NVD ↗ · NTAP-20260501-0007
CVE-2026-7168——— NVD ↗ · NTAP-20260515-0008
CVE-2026-725222026-08-10MEDIUM6.2libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode proces NVD ↗ · NTAP-20260924-0021
CVE-2026-7270——— NVD ↗ · NTAP-20260501-0003
CVE-2026-73180——— NVD ↗ · NTAP-20260902-0020
CVE-2026-73281——— NVD ↗ · NTAP-20260821-0010
CVE-2026-73282——— NVD ↗ · NTAP-20260821-0011
CVE-2026-73283——— NVD ↗ · NTAP-20260821-0012
CVE-2026-735812026-09-23MEDIUM6.5Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses NVD ↗ · NTAP-20261002-0011
CVE-2026-73832026-06-09HIGH8.1Issue summary: A signed integer overflow when sizing the destination buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap buffer overflow. Impa NVD ↗ · NTAP-20260617-0003
CVE-2026-750292026-09-16MEDIUM5.3In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on a NVD ↗ · NTAP-20260930-0016
CVE-2026-75803——— NVD ↗ · NTAP-20260902-0002
CVE-2026-759732026-09-23HIGH7.3Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and mul NVD ↗ · NTAP-20261002-0010
CVE-2026-75982026-05-01HIGH7.3A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_password of the file src/userauth.c. Such mani NVD ↗ · NTAP-20260814-0020
CVE-2026-761632026-09-16HIGH7.5If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion NVD ↗ · NTAP-20260930-0005
CVE-2026-761832026-09-23CRITICAL9.8Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue af NVD ↗ · NTAP-20261002-0002
CVE-2026-769572026-08-20MEDIUM4.9libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-5021 NVD ↗ · NTAP-20260924-0025
CVE-2026-771192026-09-16MEDIUM5.9A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answ NVD ↗ · NTAP-20260930-0013
CVE-2026-776922026-09-16HIGH7.5An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transpor NVD ↗ · NTAP-20260930-0006
CVE-2026-7771——— NVD ↗ · NTAP-20260717-0006
CVE-2026-777562026-09-23LOW3.7Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding heade NVD ↗ · NTAP-20261002-0012
CVE-2026-777622026-09-23HIGH8.1Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer NVD ↗ · NTAP-20261002-0004
CVE-2026-777912026-09-23HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomca NVD ↗ · NTAP-20261002-0008
CVE-2026-783012026-09-16MEDIUM5.8A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND autho NVD ↗ · NTAP-20260930-0014
CVE-2026-783832026-09-23HIGH7.5Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leadin NVD ↗ · NTAP-20261002-0007
CVE-2026-784372026-09-23HIGH7.3Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. Thi NVD ↗ · NTAP-20261002-0009
CVE-2026-78842026-09-14MEDIUM5.4IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include malic NVD ↗ · NTAP-20260917-0001
CVE-2026-796772026-09-23HIGH7.5Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lo NVD ↗ · NTAP-20261002-0006
CVE-2026-802742026-09-16HIGH7.5If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proo NVD ↗ · NTAP-20260930-0007
CVE-2026-815632026-09-16HIGH7.5A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resou NVD ↗ · NTAP-20260930-0008
CVE-2026-817362026-09-16HIGH7.5If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CP NVD ↗ · NTAP-20260930-0009
CVE-2026-84445——— NVD ↗ · NTAP-20260917-0012
CVE-2026-860872026-09-10MEDIUM4.3IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the s NVD ↗ · NTAP-20260917-0011
CVE-2026-860932026-09-10HIGH7.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute ar NVD ↗ · NTAP-20260917-0007
CVE-2026-862482026-09-23CRITICAL9.8CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tom NVD ↗ · NTAP-20261002-0001
CVE-2026-863502026-09-23CRITICAL9.1Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-412 NVD ↗ · NTAP-20261002-0003
CVE-2026-870222026-09-23HIGH7.5Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This iss NVD ↗ · NTAP-20261002-0005
CVE-2026-879582026-09-10HIGH8.1IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by NVD ↗ · NTAP-20260917-0004
CVE-2026-8924——— NVD ↗ · NTAP-20260731-0006
CVE-2026-8925——— NVD ↗ · NTAP-20260731-0003
CVE-2026-8926——— NVD ↗ · NTAP-20260731-0007
CVE-2026-8927——— NVD ↗ · NTAP-20260731-0008
CVE-2026-896622026-09-11CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock owner use-after-free during client teardown __destroy_client() releases a NVD ↗ · NTAP-20261002-0013
CVE-2026-896692026-09-11CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publishing it nfsd4_copy_notify() finished initi NVD ↗ · NTAP-20261002-0014
CVE-2026-896742026-09-11CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget The XDR buffer size calculatio NVD ↗ · NTAP-20261002-0015
CVE-2026-897122026-09-11CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock nfsd4_ssc_expire_umount() NVD ↗ · NTAP-20261002-0016
CVE-2026-90762026-06-09HIGH7.5Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK cipher c NVD ↗ · NTAP-20260617-0008
CVE-2026-9079——— NVD ↗ · NTAP-20260731-0004
CVE-2026-9256——— NVD ↗ · NTAP-20260605-0012
CVE-2026-9762——— NVD ↗ · NTAP-20260717-0003
CVE-2026-9828——— NVD ↗ · NTAP-20260731-0012

Years: 2026 · 2025 · 2024 · 2023 · 2022 · 2021 · 2020 · 2019 · 2018 · 2017 · 2016 · 2015 · 2014 · 2013 · 2012 · 2011 · 2010 · 2009 · 2008 · 2007 · 2006 · 2005 · 2004 · 2003 · 2002 · 1999

← CVE index · Security hub