nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-0209 CVE-2026-0209
MEDIUM
PureStorage FlashArray Purity Snapshot Retention Policy Misapplication
Record summary
CVE-2026-0209 has a selected CVSS score of 6.9 (medium).
Description
Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than configured.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlashArrayBrowse PureStorage / FlashArrayDefault status: unaffected | CVE List | 5.0.0 to ≤ 5.3.21 | affected |
| 6.0.0 to ≤ 6.4.10 | affected | ||
| 6.5.0 to ≤ 6.5.12 | affected | ||
| 6.6.0 to ≤ 6.6.11 | affected | ||
| 6.7.0 to ≤ 6.7.6 | affected | ||
| 6.8.0 to ≤ 6.8.9 | affected | ||
| 6.9.0 to ≤ 6.9.1 | affected | ||
| 6.10.0 | affected |
References
2support.purestorage.com
https://support.purestorage.com/bundle/m_security_bulletins/page/Pure_Security/topics/concept/c_security_bulletins.html