Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY2 SECURITY RECORDS

FatPipe Networks

MPVPN

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-90823 17 Sep 2026 MPVPN: 10.1.2r60p100; WARP: 10.1.2r60p100; IPVPN: 10.1.2r60p100 Customers running the affected end-of-life firmware should contact FatPipe Support to upgrade their appliances to the latest supported software release. The vulnerability has been addressed in current FatPipe software, and a remediated release is already available. As an interim mitigation pending the upgrade, leave the affected management interface disabled if it is not required, restrict management access to trusted administrative networks, use WAN access control lists to permit connections only from authorized source addresses, and avoid exposing the management interface directly to the public Internet. Update reference ↗
CVE-2026-90822 17 Sep 2026 MPVPN: 10.1.2r60p100; WARP: 10.1.2r60p100; IPVPN: 10.1.2r60p100 Customers running the affected end-of-life firmware should contact FatPipe Support to upgrade their appliances to the latest supported software release. The vulnerability has been addressed in current FatPipe software, and a remediated release is already available. As an interim mitigation pending the upgrade, leave the affected management interface disabled if it is not required, restrict management access to trusted administrative networks, use WAN access control lists to permit connections only from authorized source addresses, and avoid exposing the management interface directly to the public Internet. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.