Known Vulnerabilities for My Cloud Ex2 by Western Digital
Listed below are 1 of the newest known vulnerabilities associated with "My Cloud Ex2" by "Western Digital".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-79717 json | A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An auth... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-79671 json | Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_s... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-79659 json | Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalid... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-78541 json | A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated... | Not Provided | 2026-08-24 | 2026-08-25 |
| CVE-2026-77775 json | Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_open... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-76838 json | Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-76398 json | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the expe... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76397 json | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76395 json | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splun... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-76394 json | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could ... | Not Provided | 2026-08-19 | 2026-08-19 |