Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · westerndigital

westerndigital

· 18 Critical

Total CVEs

83

Critical

18

Products

194

Search All CVEs →

83

Products (194)

my cloud pr410042 CVEsmy cloud ex410038 CVEsmy cloud pr210037 CVEsmy cloud ex2 ultra33 CVEsmy cloud ex210028 CVEsmy cloud dl210028 CVEsmy cloud dl410028 CVEsmy cloud25 CVEswd cloud20 CVEsmy cloud mirror g218 CVEsmy cloud os18 CVEsmy cloud home16 CVEsmy cloud home firmware14 CVEsmy cloud home duo firmware13 CVEsmy cloud home duo13 CVEssandisk ibi12 CVEsmy cloud mirror gen 212 CVEsmy cloud firmware12 CVEsmy cloud pr4100 firmware11 CVEssandisk ibi firmware11 CVEsmy cloud dl4100 firmware10 CVEsmy cloud ex2100 firmware10 CVEsmy cloud ex4100 firmware10 CVEsmy cloud ex2 ultra firmware10 CVEsmy cloud dl2100 firmware10 CVEsmy cloud pr2100 firmware9 CVEsmy cloud os 58 CVEsmy cloud mirror g2 firmware7 CVEsmy cloud mirror - gen 25 CVEsmy cloud expert series ex25 CVEssweet b4 CVEssandisk x600 sd9sb8w-512g3 CVEssandisk x600 sd9sb8w-512g firmware3 CVEssandisk x600 sd9sn8w-128g3 CVEssandisk x600 sd9sn8w-128g firmware3 CVEssandisk x600 sd9sn8w-1t003 CVEssandisk x600 sd9sn8w-1t00 firmware3 CVEssandisk x600 sd9sn8w-256g3 CVEssandisk x600 sd9sn8w-256g firmware3 CVEssandisk x600 sd9sn8w-2t003 CVEssandisk x600 sd9sn8w-2t00 firmware3 CVEssandisk x600 sd9sn8w-512g3 CVEswd cloud firmware3 CVEssandisk x600 sd9sn8w-512g firmware3 CVEswd discovery3 CVEsmy cloud mirror gen23 CVEssandisk x600 sd9tb8w-512g firmware3 CVEssandisk x600 sd9tb8w-512g3 CVEssandisk x600 sd9tb8w-2t00 firmware3 CVEssandisk x600 sd9tb8w-2t003 CVEssandisk x600 sd9tb8w-256g firmware3 CVEssandisk x600 sd9tb8w-256g3 CVEssandisk x600 sd9tb8w-1t00 firmware3 CVEssandisk x600 sd9tb8w-1t003 CVEssandisk x600 sd9tb8w-128g firmware3 CVEssandisk x600 sd9tn8w-512g firmware3 CVEssandisk x600 sd9tn8w-512g3 CVEssandisk x600 sd9tn8w-2t00 firmware3 CVEssandisk x600 sd9tn8w-2t003 CVEssandisk x600 sd9tn8w-256g firmware3 CVEssandisk x600 sd9tn8w-256g3 CVEssandisk x600 sd9tn8w-1t00 firmware3 CVEssandisk x600 sd9tn8w-1t003 CVEssandisk x600 sd9tn8w-128g firmware3 CVEssandisk x600 sd9tb8w-128g3 CVEssandisk x600 sd9tn8w-128g3 CVEssandisk x600 sd9sb8w-128g3 CVEssandisk x600 sd9sb8w-128g firmware3 CVEssandisk x600 sd9sb8w-1t003 CVEssandisk x600 sd9sb8w-1t00 firmware3 CVEssandisk x600 sd9sb8w-256g3 CVEssandisk x600 sd9sb8w-256g firmware3 CVEssandisk x600 sd9sb8w-2t003 CVEssandisk x600 sd9sb8w-2t00 firmware3 CVEssandisk x400 sd8tb8u-128g-11222 CVEssandisk x400 sd8tb8u-128g-1122 firmware2 CVEssandisk x400 sd8tb8u-1t00-11222 CVEssandisk x400 sd8tb8u-1t00-1122 firmware2 CVEssandisk x400 sd8tb8u-256g-11222 CVEssandisk x400 sd8tb8u-256g-1122 firmware2 CVEssandisk x400 sd8tb8u-512g-11222 CVEssandisk x400 sd8tb8u-512g-1122 firmware2 CVEssandisk x400 sd8sn8u-256g-11222 CVEsedgerover2 CVEsmy cloud glacier2 CVEsmy cloud glacier firmware2 CVEsmy cloud mirror gen2 firmware2 CVEssandisk x300 sd7sb6s-128g2 CVEssandisk x300 sd7sb6s-128g firmware2 CVEssandisk x300 sd7sb6s-256g2 CVEssandisk x300 sd7sb6s-256g firmware2 CVEssandisk x300 sd7sb7s-010t2 CVEssandisk x300 sd7sb7s-010t firmware2 CVEssandisk x300 sd7sb7s-512g2 CVEssandisk x300 sd7sb7s-512g firmware2 CVEssandisk x300 sd7sf6s-128g2 CVEssandisk x300 sd7sf6s-128g firmware2 CVEssandisk x300 sd7sf6s-256g2 CVEssandisk x300 sd7sf6s-256g firmware2 CVEssandisk x300 sd7sf6s-512g2 CVEssandisk x300 sd7sf6s-512g firmware2 CVEssandisk x300 sd7sn6s-128g2 CVEssandisk x300 sd7sn6s-128g firmware2 CVEssandisk x300 sd7sn6s-256g2 CVEssandisk x300 sd7sn6s-256g firmware2 CVEssandisk x300 sd7sn6s-512g2 CVEssandisk x300 sd7sn6s-512g firmware2 CVEssandisk x300s sd7sb3q-064g2 CVEssandisk x300s sd7sb3q-064g firmware2 CVEssandisk x300s sd7sn3q-064g2 CVEssandisk x300s sd7sn3q-064g firmware2 CVEssandisk x300s sd7ub2q-010t2 CVEssandisk x300s sd7ub2q-010t firmware2 CVEssandisk x300s sd7ub2q-512g2 CVEssandisk x300s sd7ub2q-512g firmware2 CVEssandisk x300s sd7ub3q-128g2 CVEssandisk x300s sd7ub3q-128g firmware2 CVEssandisk x300s sd7ub3q-256g2 CVEssandisk x300s sd7ub3q-256g firmware2 CVEssandisk x300s sd7un3q-128g2 CVEssandisk x300s sd7un3q-128g firmware2 CVEssandisk x300s sd7un3q-256g2 CVEssandisk x300s sd7un3q-256g firmware2 CVEssandisk x300s sd7un3q-512g2 CVEssandisk x300s sd7un3q-512g firmware2 CVEssandisk x400 sd8sb8u-128g2 CVEssandisk x400 sd8sb8u-128g-11222 CVEssandisk x400 sd8sb8u-128g-1122 firmware2 CVEssandisk x400 sd8sb8u-128g firmware2 CVEssandisk x400 sd8sb8u-1t002 CVEssandisk x400 sd8sb8u-1t00-11222 CVEssandisk x400 sd8sb8u-1t00-1122 firmware2 CVEssandisk x400 sd8sb8u-1t00 firmware2 CVEssandisk x400 sd8sb8u-256g2 CVEssandisk x400 sd8sb8u-256g-11222 CVEssandisk x400 sd8sb8u-256g-1122 firmware2 CVEssandisk x400 sd8sb8u-256g firmware2 CVEssandisk x400 sd8sb8u-512g2 CVEssandisk x400 sd8sb8u-512g-11222 CVEssandisk x400 sd8sb8u-512g-1122 firmware2 CVEssandisk x400 sd8sb8u-512g firmware2 CVEssandisk x400 sd8sn8u-128g2 CVEssandisk x400 sd8sn8u-128g-11222 CVEssandisk x400 sd8sn8u-128g-1122 firmware2 CVEssandisk x400 sd8sn8u-128g firmware2 CVEssandisk x400 sd8sn8u-1t002 CVEssandisk x400 sd8sn8u-1t00-11222 CVEssandisk x400 sd8sn8u-1t00-1122 firmware2 CVEssandisk x400 sd8sn8u-1t00 firmware2 CVEssandisk x400 sd8sn8u-256g2 CVEssandisk x400 sd8sn8u-256g-1122 firmware2 CVEssandisk x400 sd8sn8u-256g firmware2 CVEssandisk x400 sd8sn8u-512g2 CVEssandisk x400 sd8sn8u-512g-11222 CVEssandisk x400 sd8sn8u-512g-1122 firmware2 CVEssandisk x400 sd8sn8u-512g firmware2 CVEsssd dashboard2 CVEssandisk security installer1 CVEssandisk professional g-raid 4\/8 software utility driver1 CVEssandisk professional g-raid 4\/8 software utility1 CVEssandisk privateaccess1 CVEsmycloud.com1 CVEsmy net n900c1 CVEsmy net n9001 CVEsmy net n7501 CVEsmy cloud mirror gen 2 firmware1 CVEsmy book live firmware1 CVEsmy book live1 CVEsinand ix em132 xi firmware1 CVEsinand ix em132 xi1 CVEsinand ix em132 firmware1 CVEsinand ix em1321 CVEsinand eu312 industrial ix ufs1 CVEsinand eu312 automotive xa at ufs1 CVEsinand eu311 mobile mc ufs1 CVEsinand cl em132 firmware1 CVEssandiskssddashboardsetup.exe1 CVEswesterndigitalssddashboardsetup.exe1 CVEsinand cl em1321 CVEstv live hub1 CVEstv live hub firmware1 CVEstv media player1 CVEstv media player firmware1 CVEsibi1 CVEsdashboard1 CVEsarmorlock1 CVEswd my book1 CVEswd my book firmware1 CVEswd my book live1 CVEswd my book live duo1 CVEswd my book live duo firmware1 CVEswd my book live firmware1 CVEswd my cloud1 CVEsarkeia virtual appliance firmware1 CVEs

Recent Vulnerabilities

View all 83
CVE-2023-22819MEDIUM 4.9

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue requires the attacker to already have root privileges in order to exploit this vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.5.1-104; ibi: before 9.5.1-104; My Cloud OS 5: before 5.27.161.

CVE-2023-22817MEDIUM 5.5

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that refer to loopback. This issue affects My Cloud OS 5 devices before 5.27.161, My Cloud Home, My Cloud Home Duo and SanDisk ibi devices before 9.5.1-104. 

CVE-2023-22818HIGH 7.3

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 

CVE-2023-22814CRITICAL 10.0

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.

CVE-2023-22816MEDIUM 6.0

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300.

CVE-2023-22815MEDIUM 6.2

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on vulnerable CGI files. This vulnerability can only be exploited over the network and the attacker must already have admin/root privileges to carry out the exploit. An authentication bypass is required for this exploit, thereby making it more complex. The attack may not require user interaction. Since an attacker must already be authenticated, the confidentiality impact is low while the integrity and availability impact is high.  This issue affects My Cloud OS 5 devices: before 5.26.300.

CVE-2022-36331CRITICAL 10.0

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.

CVE-2022-36328MEDIUM 5.8

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This can only be exploited once an attacker gains root privileges on the devices using an authentication bypass issue or another vulnerability.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202.

CVE-2022-36327MEDIUM 5.8

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue requires an authentication bypass issue to be triggered before this can be exploited.  This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202.

CVE-2022-36326MEDIUM 4.4

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue requires the attacker to already have root privileges in order to exploit this vulnerability.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202.

CVE-2022-29840MEDIUM 5.1

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud OS 5 devices before 5.26.202.

CVE-2022-29841HIGH 8.0

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.

CVE-2022-29842CRITICAL 9.8

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.

CVE-2022-36329MEDIUM 4.4

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.

CVE-2022-36330LOW 1.9

A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. 

CVE-2023-22813LOW 3.3

A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing authentication requirement for private IPs, a remote attacker on the same network as the device could obtain device information by convincing a victim user to visit an attacker-controlled server and issue a cross-site request. This issue affects My Cloud OS 5 Mobile App: before 4.21.0; My Cloud Home Mobile App: before 4.21.0; ibi Mobile App: before 4.21.0; My Cloud OS 5 Web App: before 4.26.0-6126; My Cloud Home Web App: before 4.26.0-6126; ibi Web App: before 4.26.0-6126.

CVE-2023-22812HIGH 7.4

SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentiality and integrity of data.

CVE-2021-36226CRITICAL 9.8

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

CVE-2021-36225HIGH 8.8

Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.

CVE-2021-36224CRITICAL 9.8

Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

CVE-2022-29844MEDIUM 6.7

A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.

CVE-2022-29843MEDIUM 6.2

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.

CVE-2022-23005HIGH 8.7

Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulnerability may exist in some systems where the Host boot ROM code implements the UFS Boot feature to boot from UFS compliant storage devices. The UFS Boot feature, as specified in the UFS standard, is provided by UFS devices to support platforms that need to download the system boot loader from external non-volatile storage locations. Several scenarios have been identified in which adversaries may disable the boot capability, or revert to an old boot loader code, if the host boot ROM code is improperly implemented. UFS Host Boot ROM implementers may be impacted by this vulnerability. UFS devices are only impacted when connected to a vulnerable UFS Host and are not independently impacted by this vulnerability. When present, the vulnerability is in the UFS Host implementation and is not a vulnerability in Western Digital UFS Devices. Western Digital has provided details of the vulnerability to the JEDEC standards body, multiple vendors of host processors, and software solutions providers.

CVE-2022-29839MEDIUM 4.1

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVE-2022-29838MEDIUM 4.3

Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.