CRITICAL 9.4 NVD
CVE-2026-28197
An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrat
An authenticated, low-privileged user with access to the NetBackup Flex
OS management shell could supply a specially crafted input to a
privileged administrative command, causing it to execute arbitrary code
with root-level permissions. Successful exploitation grants the attacker
unrestricted control over the Flex appliance host and all hosted
containers, fully compromising confidentiality, integrity, and
availability.
References
- https://github.com/cohesity/SecAdvisory/blob/master/COH-2026-0001.md
- https://www.cvcn.gov.it/cvcn/cve/CVE-2026-28197
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-09-18 via NVD.
Risk Timeline
CVE Disclosed2026-09-18 · -1 days ago
Remediation Resources
vulnfeed aggregates 14509 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.