Multiple vulnerabilities in VMware Tanzu Greenplum (August 10, 2026)
Multiple vulnerabilities were discovered in VMware Tanzu Greenplum. They allow an attacker to cause a security issue not specified by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities in VMware Tanzu Greenplum create unspecified security issues.
- Who is affected
- VMware Tanzu Greenplum deployments.
- Urgency
- Urgency unclear; vendor has not specified vulnerability type or impact.
- Action
- Monitor VMware security advisories for Tanzu Greenplum patches and details on vulnerability nature and impact.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Tanzu Greenplum
Get an email when a new Tanzu Greenplum advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0991/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-599210.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-599010.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-139496.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 94% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-558310.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-567460.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2018-117985.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 92% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-599000.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-598980.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-452050.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2019-02059.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 95% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-59921 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59901 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-13949 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55831 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56746 | coverage & exploitation status | NVD · CVE.org |
| CVE-2018-11798 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59900 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59898 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-45205 | coverage & exploitation status | NVD · CVE.org |
| CVE-2019-0205 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56745 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-43869 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54291 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55833 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56819 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59899 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Apache Commons: Vulnerability allows Denial of Servicecert-bund
- high[NEW] [high] Netty: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] PostgreSQL JDBC Driver: Vulnerability allows bypassing security measurescert-bund
- medium[NEW] [medium] Netty: Multiple vulnerabilitiescert-bund
- highGHSA-93wv-jw9v-4972: Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel i…ghsa
- unknownCVE-2026-59898: Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.13…nvd
- unknownCVE-2026-59901: Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.13…nvd
- unknownCVE-2026-59900: Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.13…nvd
- unknownCVE-2026-59899: Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.13…nvd
- mediumCVE-2026-59921: Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.13…nvd
- mediumGHSA-gcjf-9mgh-3p7g: Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoderghsa
- highGHSA-558v-64gr-wgg4: Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hangghsa
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21