Content Library · Advisory

Advisory 2026

Browse 982 2026 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

2026-09-11-ntap-kernel-vuln-27012

Source: https://security.netapp.com/adv_api/advisory/?limit=30

Linux kernel versions are susceptible to CVE-2024-27012, a high-severity vulnerability (CVSS 7.8) that could allow disclosure of sensitive information, data modification, or Denial of Service (DoS) when exploited against NetApp products. The kernel-level flaw requires attention from system administrators running affected Linux kernel versions alongside NetApp infrastructure.

Open source
Advisory

2026-09-04-ntap-20260903-0009

Source: https://security.netapp.com/advisory/NTAP-20260903-0009/

CVEs: CVE-2026-11972. Affected products (excerpt): Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI.

Open source
Advisory

2026-09-04-ntap-20260903-0001

Source: https://security.netapp.com/advisory/NTAP-20260903-0001/

CVEs: CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076. Affected products (excerpt): .

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58094-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0006

CVE-2026-58094 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user can escalate privileges. Impact: disclosure of sensitive information, data modification, or DoS. Part of the Sept 3 FreeBSD local-privilege-escalation cluster. Review the NetApp affected-products table in the advisory and align patching with NTAP-20260903-0004 / -0005 / -0007 to avoid partial remediation.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58093-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0007

CVE-2026-58093 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user can escalate privileges. Successful exploitation can lead to disclosure of sensitive information, data modification, or Denial of Service. Fourth CVE in the Sept 3 FreeBSD privilege-escalation cluster (with -58090 / -58091 / -58094). Apply FreeBSD security errata together to keep NetApp controllers in a consistent patched state.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58092-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0008

CVE-2026-58092 FreeBSD Vulnerability in NetApp Products. FreeBSD versions 15.0 and later are susceptible. Certain mac_do rules can be abused to set a process' group ID to 0 (effective root-equivalent group), leading to disclosure of sensitive information or addition or modification of data. The mac_do(4) framework is uncommon on production NetApp controllers but applies to ONTAP Select / FreeBSD-based NetApp edge nodes where jail-friendly mac_do policies are in use. See the advisory for affected products and remediation.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58091-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0005

CVE-2026-58091 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user can escalate privileges. Successful exploitation can lead to disclosure of sensitive information, addition or modification of data, or Denial of Service. Part of the Sept 3 FreeBSD local-privilege-escalation cluster (also CVE-2026-58090, -58093, -58094). Plan a coordinated FreeBSD security patch window across affected NetApp controllers.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58090-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0004

CVE-2026-58090 FreeBSD Vulnerability in NetApp Products. FreeBSD versions 15.0 and later are susceptible. An unprivileged local user can escalate privileges. Impact ranges from disclosure of sensitive information to data modification or DoS. NetApp-affected products and remediation steps are listed in the advisory body; track alongside CVE-2026-58091 / -58093 / -58094 (same privilege-escalation family, also published Sept 3) for a single change window.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-58089-freebsd-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0003

CVE-2026-58089 FreeBSD Vulnerability in NetApp Products. All supported versions of FreeBSD are susceptible. An unprivileged local user who has attached PMCs (Performance Monitoring Counters) to a process can continue monitoring it after the process executes a setuid or setgid binary, leading to disclosure of sensitive information, addition or modification of data, or Denial of Service. The bug class is a process-credentials leak via hwpmc(4); applies wherever NetApp ships FreeBSD-derived code paths with PMC tooling enabled.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-53362-linux-kernel-vulnerability-in-netapp-products

Source: https://security.netapp.com/advisory/NTAP-20260903-0010

CVE-2026-53362 Linux Kernel Vulnerability in NetApp Products. Linux kernel versions 6.0-rc1 through 6.1.176, 6.13-rc1 through 6.18.37, 6.19-rc1 through 7.1.2, 6.2-rc1 through 6.6.143, and 6.7-rc1 through 6.12.94 are susceptible. Successful exploitation can lead to disclosure of sensitive information, addition or modification of data, or Denial of Service. Applies wherever NetApp ships Linux-based nodes — ONTAP Select on Linux hypervisors, BlueXP/Cloud Manager SaaS connectors, StorageGRID appliance nodes, and AI control-plane pods running AIPod with NVIDIA — see the advisory's affected-products table for exact applicability and remediation per ONTAP / BlueXP / StorageGRID release.

Open source
Advisory

2026-09-03-2026-09-03-cve-2026-11972-python-vulnerability-in-netapp-products

Source: https://security.netapp.com/advisory/NTAP-20260903-0009

CVE-2026-11972 Python Vulnerability in NetApp Products. Python versions 2.3 through 3.10.20, 3.11.0a1 through 3.11.15, 3.12.0a1 through 3.12.13, 3.13.0a1 through 3.13.14, 3.14.0a1 through 3.14.6, and 3.15.0a1 through 3.15.0b3 are susceptible. Successful exploitation leads to Denial of Service (DoS). Because NetApp management tooling (OnCommand Workflow Automation, Active IQ, Docker images behind BlueXP connectors, Ansible modules) ships CPython, customers should confirm the bundled Python version against the advisory's affected-products list before the next NetApp software update window.

Open source
Advisory

2026-09-03-2026-09-03-august-2026-freebsd-point-to-point-protocol-vulner

Source: https://security.netapp.com/advisory/NTAP-20260903-0002

August 2026 FreeBSD Point-to-Point Protocol (PPP) Vulnerabilities in NetApp Products. All supported FreeBSD versions are susceptible. CVEs: CVE-2026-58095, CVE-2026-58096, CVE-2026-58097. A malicious PPP peer (CVE-2026-58095 or CVE-2026-58096) or a local user with access to the ppp(8) command interface (CVE-2026-58097) can crash ppp(8) or potentially execute arbitrary code as root. Successful exploitation can lead to disclosure of sensitive information, modification of data, or DoS. PPP exposure is uncommon on production NetApp storage but applies to ONTAP Select and any deployment where FreeBSD's ppp(8) is reachable; review the affected-product list in the advisory before scheduling the FreeBSD security update.

Open source
Advisory

2026-09-03-2026-09-03-august-2026-freebsd-openssl-vulnerabilities-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260903-0001

August 2026 FreeBSD OpenSSL Vulnerabilities in NetApp Products. Multi-CVE roll-up covering OpenSSL vulnerabilities shipped in supported FreeBSD releases prior to 15.1-RELEASE-p3, 15.0-RELEASE-p13, and 14.4-RELEASE-p9. CVEs: CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076. Successful exploitation can lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS), or potential remote code execution. Because ONTAP 9.x relies on FreeBSD internally and ONTAP Select / ONTAP on third-party hosts may carry upstream OpenSSL packages, customers should track the per-CVE remediation matrix in the advisory text. Cross-references the Sept 2 individual OpenSSL CVEs (NTAP-20260902-0001..-0009) which were published one day earlier.

Open source
Advisory

CVE-2026-73180 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0020

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.43 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-68763 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0019

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.39 through 9.0.120, and 8.5.59 through 8.5.100 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-68569 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0016

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-68525 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0013

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-66422 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0015

Apache Tomcat versions 1.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.25 through 9.0.120, 8.5.46 through 8.5.100 (EOL), and 7.0.97 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65905 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0011

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.30 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65637 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0010

Apache Tomcat versions 11.0.20 through 11.0.24, 10.1.53 through 10.1.57, and 9.0.115 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65183 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0014

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.42 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-65182 Apache Tomcat Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0012

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-63076 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0008

OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could allow a remote, unauthenticated attacker to crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service (DoS).

Open source
Advisory

CVE-2026-63075 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0007

OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a remote peer that can complete a QUIC handshake to cause connection-scoped memory growth which may lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-63074 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0009

OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process observing unbounded memory growth in the event that a malicious client repeatedly sends requests containing unique extra certificates, potentially leading to OOM conditions.

Open source
Advisory

CVE-2026-63073 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0001

OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a malicious or intercepted CMP endpoint to crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.

Open source
Advisory

CVE-2026-63072 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0006

OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, and 1.1.1 are susceptible to a vulnerability which when successfully exploited could allow an attacker who supplies a crafted CMS message to trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service (DoS).

Open source
Advisory

CVE-2026-54874 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0005

OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could allow a peer to use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service (DoS).

Open source
Advisory

CVE-2026-18798 OpenSSL Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260902-0004

OpenSSL versions 4.0, 3.6, and 3.5 are susceptible to a vulnerability which when successfully exploited could lead to a double free resulting in heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-75803-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0002

CVE-2026-75803 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-75803. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to applications calling EVP_Cipher() accepting forged messages.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-73180-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0020

CVE-2026-73180 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-73180. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.43 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-68763-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0019

CVE-2026-68763 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-68763. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.39 through 9.0.120, and 8.5.59 through 8.5.100 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-68569-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0016

CVE-2026-68569 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-68569. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-68525-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0013

CVE-2026-68525 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-68525. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-66422-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0015

CVE-2026-66422 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-66422. Apache Tomcat versions 1.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.25 through 9.0.120, 8.5.46 through 8.5.100 (EOL), and 7.0.97 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-66299-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0018

CVE-2026-66299 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-66299. Apache Tomcat versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65927-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0017

CVE-2026-65927 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65927. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.0.M1 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65905-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0011

CVE-2026-65905 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65905. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.30 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65637-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0010

CVE-2026-65637 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65637. Apache Tomcat versions 11.0.20 through 11.0.24, 10.1.53 through 10.1.57, and 9.0.115 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65183-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0014

CVE-2026-65183 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65183. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.42 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-65182-apache-tomcat-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260902-0012

CVE-2026-65182 Apache Tomcat Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-65182. Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63076-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0008

CVE-2026-63076 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63076. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could allow a remote, unauthenticated attacker to crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63075-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0007

CVE-2026-63075 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63075. OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a remote peer that can complete a QUIC handshake to cause connection-scoped memory growth which may lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63074-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0009

CVE-2026-63074 OpenSSL Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-63074. OpenSSL versions 4.0, 3.6, 3.5, 3.4, and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process observing unbounded memory growth in the event that a malicious client repeatedly sends requests containing unique extra certificates, potentially leading to OOM conditions.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63073-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0001

CVE-2026-63073 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63073. OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could allow a malicious or intercepted CMP endpoint to crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender.

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-63072-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0006

CVE-2026-63072 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-63072. OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, and 1.1.1 are susceptible to a vulnerability which when successfully exploited could allow an attacker who supplies a crafted CMS message to trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-54874-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0005

CVE-2026-54874 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54874. OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could allow a peer to use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-18798-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0004

CVE-2026-18798 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-18798. OpenSSL versions 4.0, 3.6, and 3.5 are susceptible to a vulnerability which when successfully exploited could lead to a double free resulting in heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-09-02-cve-2026-14457-openssl-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260902-0003

CVE-2026-14457 OpenSSL Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-14457. OpenSSL versions 4.0, 3.6, 3.5, and 3.4 are susceptible to a vulnerability which when successfully exploited could cause an application abort leading to a Denial of Service (DoS).

Open source
Advisory

NetApp Advisories: 62 new entries published Aug 21–28 (sweep batch)

Source: NetApp Product Security (security.netapp.com advisory API)

This research sweep picked up 62 NetApp security advisories newly updated between Aug 21 and Aug 28, 2026 — covering OpenSSL, Node.js, Linux Kernel, Python, CPython, NGINX, Samba, MongoDB Drivers, Golang, Handlebars, Angular, Bouncy Castle, Runc, Apache ActiveMQ, Java Platform, ISC BIND, 7-Zip, GnuTLS, Glib, libxml2, libpng, Axios, Urllib3, PyJWT, pyca/cryptography, pyOpenSSL, Nghttp2, Node-Tar, qs, Jaraco, and more. Affected products span ONTAP, StorageGRID, BlueXP, SnapCenter, ONTAP Select, and the NetApp Manageability SDK. Notable interim entries: NTAP-20260123-0012 (January 2026 Java PS), NTAP-20260220-0013 (libxml2), NTAP-20260730-0005 (ISC BIND), and the July–August Linux Kernel CVE batch. Each advisory is in this library as a standalone record under the Advisory category.

Open source
Advisory

NetApp Advisories: NTAP-20260828-0021 — StorageGRID DoS (CVE-2026-22056)

Source: NetApp Product Security

NTAP-20260828-0021 is an Interim advisory for CVE-2026-22056, a Denial of Service vulnerability in StorageGRID (formerly StorageGRID Webscale). Successful exploitation could lead to DoS. StorageGRID operators should watch for the fix and check the affected-versions list; this is a follow-on to the Aug 28 batch of 20 advisories (NTAP-20260828-0001 to -0020) already covered.

Open source
Advisory

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0005/

NetApp published this interim advisory covering CVE-2026-49429, CVE-2026-49430, CVE-2026-49431; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0005

NetApp published security advisory NTAP-20260828-0005 on 2026-08-28. All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets.

Open source
Advisory

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0005/

All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets.

Open source
Advisory

January 2026 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260123-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-21932, CVE-2026-21945, CVE-2026-21925, CVE-2026-21933. The advisory affects Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: Fix status not yet published. Impact: Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data as well as unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized creation, deletion or modification access Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0016/

NetApp published this interim advisory covering CVE-2026-59889; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0016

NetApp published security advisory NTAP-20260828-0016 on 2026-08-28, CVE-2026-59889. FasterXML Jackson Databind versions 2.18.0-rc1 through 2.18.8, 2.18.0-rc1 through 2.18.8, 2.21.0 through 2.21.4, 2.21.0 through 2.21.4, 2.22.0 through 2.22.0, 2.22.0 through 2.22.0, 3.0.0-rc1 through 3.1.4, 3.0.0-rc1 through 3.1.4, 3.2.0 through 3.2.0, and 3.2.0 through 3.2.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0016/

FasterXML Jackson Databind versions 2.18.0-rc1 through 2.18.8, 2.18.0-rc1 through 2.18.8, 2.21.0 through 2.21.4, 2.21.0 through 2.21.4, 2.22.0 through 2.22.0, 2.22.0 through 2.22.0, 3.0.0-rc1 through 3.1.4, 3.0.0-rc1 through 3.1.4, 3.2.0 through 3.2.0, and 3.2.0 through 3.2.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0015/

NetApp published this interim advisory covering CVE-2026-59888; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0015

NetApp published security advisory NTAP-20260828-0015 on 2026-08-28, CVE-2026-59888. FasterXML Jackson Databind versions 2.15.0-rc1 through 2.18.7, 2.19.0-rc2 through 2.21.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data.

Open source
Advisory

CVE-2026-59875 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0004/

NetApp published this interim advisory covering CVE-2026-59875; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-59875 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0004

NetApp published security advisory NTAP-20260828-0004 on 2026-08-28, CVE-2026-59875. Tar versions prior to 7.5.17 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59874 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0002/

NetApp published this interim advisory covering CVE-2026-59874; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59874 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0002

NetApp published security advisory NTAP-20260828-0002 on 2026-08-28, CVE-2026-59874. Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59873 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0001/

NetApp published this interim advisory covering CVE-2026-59873; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59873 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0001

NetApp published security advisory NTAP-20260828-0001 on 2026-08-28, CVE-2026-59873. Tar versions prior to 7.5.19 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59871 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0003/

NetApp published this interim advisory covering CVE-2026-59871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-59871 Tar Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0003

NetApp published security advisory NTAP-20260828-0003 on 2026-08-28, CVE-2026-59871. Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0009/

NetApp published this interim advisory covering CVE-2026-59250; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0009

NetApp published security advisory NTAP-20260828-0009 on 2026-08-28, CVE-2026-59250. Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0009/

Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0008/

NetApp published this interim advisory covering CVE-2026-55953; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0008

NetApp published security advisory NTAP-20260828-0008 on 2026-08-28, CVE-2026-55953. Erlang/OTP versions R13B03 prior to 27.3.4.15, from 28.0 prior to 28.5.0.4, and from 29.0 prior to 29.0.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0008/

Erlang/OTP versions R13B03 prior to 27.3.4.15, from 28.0 prior to 28.5.0.4, and from 29.0 prior to 29.0.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0014/

NetApp published this interim advisory covering CVE-2026-54513; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0014

NetApp published security advisory NTAP-20260828-0014 on 2026-08-28, CVE-2026-54513. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0014/

FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0013/

NetApp published this interim advisory covering CVE-2026-54512; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0013

NetApp published security advisory NTAP-20260828-0013 on 2026-08-28, CVE-2026-54512. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0013/

FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-54370 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0011/

NetApp published this interim advisory covering CVE-2026-54370; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54370 Acl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0011

NetApp published security advisory NTAP-20260828-0011 on 2026-08-28, CVE-2026-54370. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-54370 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0011/

Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-54369 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0010/

NetApp published this interim advisory covering CVE-2026-54369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54369 Acl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0010

NetApp published security advisory NTAP-20260828-0010 on 2026-08-28, CVE-2026-54369. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-54369 Acl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0010/

Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

CVE-2026-45292 OpenTelemetry Java Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0020/

NetApp published this interim advisory covering CVE-2026-45292; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44604 RPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0018/

NetApp published this interim advisory covering CVE-2026-44604; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44604 RPM Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0018

NetApp published security advisory NTAP-20260828-0018 on 2026-08-28, CVE-2026-44604. RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-44604 RPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0018/

RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-44604 Attr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0012/

NetApp published this interim advisory covering CVE-2026-54371; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44604 Attr Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0012

NetApp published security advisory NTAP-20260828-0012 on 2026-08-28, CVE-2026-44604. Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-44170 Mariadb Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0019/

NetApp published this interim advisory covering CVE-2026-44170; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44170 Mariadb Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0019

NetApp published security advisory NTAP-20260828-0019 on 2026-08-28, CVE-2026-44170. MariaDB versions 10.6.1 prior to 10.6.25, 10.11.1 prior to 10.11.17, 11.4.1 prior to 11.4.11, 11.8.1 prior to 11.8.7, and 12.3.1 prior to 12.3.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-44170 Mariadb Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0019/

MariaDB versions 10.6.1 prior to 10.6.25, 10.11.1 prior to 10.11.17, 11.4.1 prior to 11.4.11, 11.8.1 prior to 11.8.7, and 12.3.1 prior to 12.3.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-31790 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0017 (2026-08-28) (interim — details may evolve) covering CVE-2026-31790. The advisory affects E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-31789 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0011 (2026-08-28) (interim — details may evolve) covering CVE-2026-31789. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp LOADER 8.x. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-31402 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0008 (2026-08-28) (interim — details may evolve) covering CVE-2026-31402. The advisory affects ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28390 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-28390. The advisory affects Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28389 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0013 (2026-08-28) (interim — details may evolve) covering CVE-2026-28389. The advisory affects Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28388 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0014 (2026-08-28) (interim — details may evolve) covering CVE-2026-28388. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-28387 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0015 (2026-08-28) (interim — details may evolve) covering CVE-2026-28387. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-27141 Golang Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-27141. The advisory affects Astra Control Center - NetApp Kubernetes Monitoring Operator. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-27135 Nghttp2 Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0011 (2026-08-28) (interim — details may evolve) covering CVE-2026-27135. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-25639 Axios Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260313-0010 (2026-08-28) (interim — details may evolve) covering CVE-2026-25639. The advisory affects NetApp Shift Toolkit, ONTAP tools for VMware vSphere 10, Storage Manager for ProxMox. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23949 Jaraco.Context Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260327-0011 (2026-08-28) (interim — details may evolve) covering CVE-2026-23949. The advisory affects ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-2391 Qs Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260515-0010 (2026-08-28) (interim — details may evolve) covering CVE-2026-2391. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23095 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260424-0020 (2026-08-28) (interim — details may evolve) covering CVE-2026-23095. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23001 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260305-0018 (2026-08-28) (interim — details may evolve) covering CVE-2026-23001. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22990 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260508-0002 (2026-08-28) (interim — details may evolve) covering CVE-2026-22990. The advisory affects ONTAP tools for VMware vSphere 10. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22796 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260204-0004 (2026-08-28) (interim — details may evolve) covering CVE-2026-22796. The advisory affects Brocade SAN Navigator (SANnav), Management Services for Element Software and NetApp HCI, NetApp Console Agent Container (adc), NetApp Console Agent Container (cbs), NetApp Console Agent Container (cbs-backend). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22795 OpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260204-0005 (2026-08-28) (interim — details may evolve) covering CVE-2026-22795. The advisory affects Brocade SAN Navigator (SANnav), Management Services for Element Software and NetApp HCI, NetApp Console Agent Container (cbs-backend), NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp LOADER 8.x. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21714 Node.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-21714. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21710 Node.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0013 (2026-08-28) (interim — details may evolve) covering CVE-2026-21710. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21637 Node.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260313-0009 (2026-08-28) (interim — details may evolve) covering CVE-2026-21637. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-21441 Urllib3 Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260130-0010 (2026-08-28) (interim — details may evolve) covering CVE-2026-21441. The advisory affects Management Services for Element Software and NetApp HCI, NetApp Data Classification. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-18963 Keycloak Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0006/

NetApp published this interim advisory covering CVE-2026-18963; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18963 Keycloak Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0006

NetApp published security advisory NTAP-20260828-0006 on 2026-08-28, CVE-2026-18963. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0017/

NetApp published this interim advisory covering CVE-2026-17106; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0017

NetApp published security advisory NTAP-20260828-0017 on 2026-08-28, CVE-2026-17106. Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0017/

Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-15571 Keycloak Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0007/

NetApp published this interim advisory covering CVE-2026-15571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-15571 Keycloak Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0007

NetApp published security advisory NTAP-20260828-0007 on 2026-08-28, CVE-2026-15571. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-15308 CPython Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0016 (2026-08-28) (interim — details may evolve) covering CVE-2026-15308. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-12617 ISC BIND Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260730-0005 (2026-08-28) (interim — details may evolve) covering CVE-2026-12617. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-0990 Libxml2 Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260220-0013 (2026-08-28) (interim — details may evolve) covering CVE-2026-0990. The advisory affects NetApp Manageability SDK, ONTAP 9. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

April 2026 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260429-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: 1 fix entries. Impact: Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized access to critical data or complete access to all Oracle Java SE accessible data or the unauthorized ability to cause a partial Denial of Se Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

2026-09-02-2026-08-28-june-2026-freebsd-zfs-vulnerabilities-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0005

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-49429, CVE-2026-49430, CVE-2026-49431. All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59889-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0016

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59889. FasterXML Jackson Databind versions 2.18.0-rc1 through 2.18.8, 2.18.0-rc1 through 2.18.8, 2.21.0 through 2.21.4, 2.21.0 through 2.21.4, 2.22.0 through 2.22.0, 2.22.0 through 2.22.0, 3.0.0-rc1 through 3.1.4, 3.0.0-rc1 through 3.1.4, 3.2.0 through 3.2.0, and 3.2.0 through 3.2.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59888-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0015

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59888. FasterXML Jackson Databind versions 2.15.0-rc1 through 2.18.7, 2.19.0-rc2 through 2.21.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59875-tar-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0004

CVE-2026-59875 Tar Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-59875. Tar versions prior to 7.5.17 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59871-tar-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0003

CVE-2026-59871 Tar Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-59871. Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59250-erlang-otp-vulnerability-in-netapp

Source: https://security.netapp.com/advisory/NTAP-20260828-0009

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59250. Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-55953-erlang-otp-vulnerability-in-netapp

Source: https://security.netapp.com/advisory/NTAP-20260828-0008

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-55953. Erlang/OTP versions R13B03 prior to 27.3.4.15, from 28.0 prior to 28.5.0.4, and from 29.0 prior to 29.0.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54513-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0014

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54513. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54512-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0013

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54512. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54370-acl-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0011

CVE-2026-54370 Acl Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54370. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54369-acl-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0010

CVE-2026-54369 Acl Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54369. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-45292-opentelemetry-java-vulnerability-i

Source: https://security.netapp.com/advisory/NTAP-20260828-0020

CVE-2026-45292 OpenTelemetry Java Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-45292. OpenTelemetry Java versions through 1.61.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44604-rpm-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0018

CVE-2026-44604 RPM Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-44604. RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44604-attr-vulnerability-in-netapp-produ

Source: https://security.netapp.com/advisory/NTAP-20260828-0012

CVE-2026-44604 Attr Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54371. Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44170-mariadb-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260828-0019

CVE-2026-44170 Mariadb Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-44170. MariaDB versions 10.6.1 prior to 10.6.25, 10.11.1 prior to 10.11.17, 11.4.1 prior to 11.4.11, 11.8.1 prior to 11.8.7, and 12.3.1 prior to 12.3.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-22056-denial-of-service-vulnerability-in

Source: https://security.netapp.com/advisory/NTAP-20260828-0021

CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale). Affected: StorageGRID (formerly StorageGRID Webscale). CVEs: CVE-2026-22056. StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-18963-keycloak-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0006

CVE-2026-18963 Keycloak Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-18963. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-17106-docker-engine-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260828-0017

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-17106. Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-15571-keycloak-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0007

CVE-2026-15571 Keycloak Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-15571. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-3644 Python Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0020 (2026-08-26) (interim — details may evolve) covering CVE-2026-3644. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-34282 Java Platform Standard Edition Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260429-0011 (2026-08-26) (interim — details may evolve) covering CVE-2026-34282. The advisory affects Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: 1 fix entries. Impact: Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33939 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0008 (2026-08-26) (interim — details may evolve) covering CVE-2026-33939. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-32597 PyJWT Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0010 (2026-08-26) (interim — details may evolve) covering CVE-2026-32597. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-60005 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260730-0010 (2026-08-25) (interim — details may evolve) covering CVE-2026-60005. The advisory affects NetApp Console Agent Container (static-file-server). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-42533 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0001 (2026-08-25) (interim — details may evolve) covering CVE-2026-42533. The advisory affects NetApp Console Agent Container (static-file-server). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4046 GNU C Library (glibc) Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260422-0003 (2026-08-25) (interim — details may evolve) covering CVE-2026-4046. The advisory affects Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-27448 pyOpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0013 (2026-08-25) (interim — details may evolve) covering CVE-2026-27448. The advisory affects NetApp Data Classification. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-42945 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260522-0011 (2026-08-24) (interim — details may evolve) covering CVE-2026-42945. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22801 Libpng Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260130-0011 (2026-08-24) (interim — details may evolve) covering CVE-2026-22801. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

NetApp Advisories Batch — NTAP-20260821-0001 to -0015

Source: security.netapp.com advisory API

Fifteen new NetApp advisories published Aug 21, 2026: Node.js (CVE-2026-58043 7.5, CVE-2026-1245 6.5), OpenSSL DoS (CVE-2026-14456 7.5), cJSON data modification (CVE-2026-29036 8.7), Spring Boot info disclosure (CVE-2026-40976 9.1), Libpng (CVE-2026-22695 6.1), August MySQL Connector/ODBC batch, Java SE (CVE-2026-70906 + monthly batch), OpenSSH trio (CVE-2026-73281/82/83), TPM 2.0 (CVE-2026-6726 8.5, CVE-2026-6727 8.3), and Samba CVE-2026-58216 5.3. Admins running ONTAP tools, ONTAP Select/ASA r2 plugins, or storage management stacks should check affected-product lists and patch.

Open source
Advisory

May 2026 GnuTLS Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0002 (2026-08-21) (interim — details may evolve) covering CVE-2026-33845, CVE-2026-33846, CVE-2026-3833. The advisory affects Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP Select Deploy administration utility. Fix status: 1 fix entries. Impact: Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

May 2026 Apache ActiveMQ Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260710-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-42253, CVE-2026-42588, CVE-2026-45505, CVE-2026-46605, CVE-2026-49157, CVE-2026-49270. The advisory affects E-Series SANtricity Unified Manager and Web Services Proxy, SANtricity Storage Plugin for vCenter. Fix status: Fix status not yet published. Impact: Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-9256 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260605-0012 (2026-08-21) (interim — details may evolve) covering CVE-2026-9256. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-70906 Java SE Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0008/

NetApp published this interim advisory covering CVE-2026-70906; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6949 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0020/

NetApp published this interim advisory covering CVE-2026-6949; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6100 CPython Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0015 (2026-08-21) (interim — details may evolve) covering CVE-2026-6100. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-58224 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0019/

NetApp published this final advisory covering CVE-2026-58224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58222 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0018/

NetApp published this interim advisory covering CVE-2026-58222; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58221 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0017/

NetApp published this interim advisory covering CVE-2026-58221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58218 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0016/

NetApp published this interim advisory covering CVE-2026-58218; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58216 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0015/

NetApp published this interim advisory covering CVE-2026-58216; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58043 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0001/

NetApp published this interim advisory covering CVE-2026-58043; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46300 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260522-0016 (2026-08-21) (interim — details may evolve) covering CVE-2026-46300. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4519 Python Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0019 (2026-08-21) (interim — details may evolve) covering CVE-2026-4519. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4408 Samba Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260527-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-4408. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-40976 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0005/

NetApp published this interim advisory covering CVE-2026-40976; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34197 Apache ActiveMQ Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0001 (2026-08-21) covering CVE-2026-34197. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33941 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0006 (2026-08-21) (interim — details may evolve) covering CVE-2026-33941. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33940 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0007 (2026-08-21) (interim — details may evolve) covering CVE-2026-33940. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33938 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0009 (2026-08-21) (interim — details may evolve) covering CVE-2026-33938. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-29036 cJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0004/

NetApp published this interim advisory covering CVE-2026-29036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-26007 pyca/cryptography Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260311-0010 (2026-08-21) (interim — details may evolve) covering CVE-2026-26007. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-24842 Node-tar Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260422-0018 (2026-08-21) (interim — details may evolve) covering CVE-2026-24842. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23950 Node-Tar Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0003 (2026-08-21) (interim — details may evolve) covering CVE-2026-23950. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23231 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0013 (2026-08-21) (interim — details may evolve) covering CVE-2026-23231. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-2303 MongoDB Drivers Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260626-0017 (2026-08-21) (interim — details may evolve) covering CVE-2026-2303. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22988 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260305-0017 (2026-08-21) (interim — details may evolve) covering CVE-2026-22988. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22984 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260508-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-22984. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22695 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0006/

NetApp published this interim advisory covering CVE-2026-22695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22610 Angular Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260311-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-22610. The advisory affects Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1485 GLib Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-1485. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1484 GLib Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0003 (2026-08-21) (interim — details may evolve) covering CVE-2026-1484. The advisory affects Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-14456 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0003/

NetApp published this interim advisory covering CVE-2026-14456; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-14266 7-Zip Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0010 (2026-08-21) (interim — details may evolve) covering CVE-2026-14266. The advisory affects Active IQ Unified Manager for Microsoft Windows. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1245 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0002/

NetApp published this interim advisory covering CVE-2026-1245; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-0861 GNU C Library (glibc) Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0005 (2026-08-21) (interim — details may evolve) covering CVE-2026-0861. The advisory affects Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, NetApp HCI Baseboard Management Controller (BMC) - H610S, Trident. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-8885 Bouncy Castle Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20250912-0012 (2026-08-21) (interim — details may evolve) covering CVE-2025-8885. The advisory affects Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, ONTAP tools for VMware vSphere 10. Fix status: 3 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-64506 Libpng Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260116-0005 (2026-08-21) (interim — details may evolve) covering CVE-2025-64506. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-52565 Runc Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20251121-0002 (2026-08-21) (interim — details may evolve) covering CVE-2025-52565. The advisory affects Astra Control Center, ONTAP tools for VMware vSphere 10. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

August 2026 MySQL Connector/ODBC Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0007/

NetApp published this interim advisory covering CVE-2026-71084, CVE-2026-71079, CVE-2026-71073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260821-0014

Source: https://security.netapp.com/advisory/NTAP-20260821-0014/

NetApp security advisory NTAP-20260821-0014. CVEs: CVE-2026-6727. The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which exposes a timing side-channel in RSA OAEP decryption, enabling an attacker to decrypt sensitive blobs (import blobs, credential blobs, and session salts) encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), or to falsify TPM 2.0 Attestation Keys.

Open source
Advisory

2026-09-01-ntap-20260821-0013

Source: https://security.netapp.com/advisory/NTAP-20260821-0013/

NetApp security advisory NTAP-20260821-0013. CVEs: CVE-2026-6726. The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which when exploited could allow improper reuse of object slots between key/data objects and hash contexts, enabling an attacker to falsify TPM attestations and credentials.

Open source
Advisory

2026-09-01-ntap-20260821-0012

Source: https://security.netapp.com/advisory/NTAP-20260821-0012/

NetApp security advisory NTAP-20260821-0012. CVEs: CVE-2026-73283. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0011

Source: https://security.netapp.com/advisory/NTAP-20260821-0011/

NetApp security advisory NTAP-20260821-0011. CVEs: CVE-2026-73282. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0010

Source: https://security.netapp.com/advisory/NTAP-20260821-0010/

NetApp security advisory NTAP-20260821-0010. CVEs: CVE-2026-73281. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0009

Source: https://security.netapp.com/advisory/NTAP-20260821-0009/

NetApp security advisory NTAP-20260821-0009. CVEs: CVE-2026-61308, CVE-2026-70907, CVE-2026-60589. Java SE versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2 are susceptible to vulnerabilities that allow unauthenticated attackers with network access via multiple protocols (including HTTP and TLS) to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details.

Open source
Advisory

NetApp Advisories Batch — NTAP-20260814-0001 to -0020

Source: security.netapp.com advisory API

Twenty advisories published Aug 14, 2026: five Linux Kernel CVEs rated up to 9.8 (CVE-2026-31589, -64391, -64534, -64535, -64319), Intel UEFI SA-01234, six IBM Db2 vulnerabilities (CVE-2026-10534/-10543/-18097/-45205/-16480/-18096), six FreeBSD vulnerabilities (CVE-2026-58083 through -58088), OpenSSL CVE-2026-54876, and Libssh2 CVE-2026-7598. Several Linux Kernel items carry critical 9.8 scores with potential full system impact — prioritize reviewing affected products if you run ONTAP Medius/hosting stacks or NetApp-supported Linux-based appliances.

Open source
Advisory

Intel SA-01234 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0006/

NetApp published this interim advisory covering CVE-2025-20105, CVE-2025-20064, CVE-2025-20028, CVE-2025-20068, CVE-2025-20027, CVE-2025-22850, CVE-2025-22444, CVE-2025-20005, CVE-2025-20073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-7598 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0020/

NetApp published this interim advisory covering CVE-2026-7598; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-64535 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0004/

NetApp published this interim advisory covering CVE-2026-64535; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-64391 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0002/

NetApp published this interim advisory covering CVE-2026-64391; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-64319 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0005/

NetApp published this interim advisory covering CVE-2026-64319; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58088 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0015/

NetApp published this final advisory covering CVE-2026-58088; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58087 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0014/

NetApp published this final advisory covering CVE-2026-58087; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58086 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0017/

NetApp published this interim advisory covering CVE-2026-58086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58085 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0016/

NetApp published this interim advisory covering CVE-2026-58085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58084 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0018/

NetApp published this interim advisory covering CVE-2026-58084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58083 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0013/

NetApp published this final advisory covering CVE-2026-58083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54876 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0019/

NetApp published this interim advisory covering CVE-2026-54876; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45205 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0010/

NetApp published this interim advisory covering CVE-2026-45205; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31589 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0001/

NetApp published this interim advisory covering CVE-2026-31589; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18097 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0009/

NetApp published this final advisory covering CVE-2026-18097; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18096 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0012/

NetApp published this final advisory covering CVE-2026-18096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-16480 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0011/

NetApp published this final advisory covering CVE-2026-16480; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10543 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0008/

NetApp published this interim advisory covering CVE-2026-10543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10534 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0007/

NetApp published this final advisory covering CVE-2026-10534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260814-0003

Source: https://security.netapp.com/advisory/NTAP-20260814-0003/

NetApp security advisory NTAP-20260814-0003. CVEs: CVE-2026-64534. Linux kernel versions prior to 5.10.261, 5.11.0 prior to 5.15.212, 5.16.0 prior to 6.1.178, 6.2.0 prior to 6.6.145, 6.7.0 prior to 6.12.97, 6.13.0 prior to 6.18.40, and 6.19.0 prior to 7.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

NetApp Advisories Batch — NTAP-20260807-0001 to -0020

Source: security.netapp.com advisory API

Twenty advisories published Aug 7, 2026: four Libssh2 CVEs (CVE-2026-66032/-33/-34/-35), five Linux Kernel issues including CVE-2026-64531, Tar CVE-2026-53655, ten Libssh CVEs (CVE-2026-15370, -59844/-59845/-59847/-59850/-59846/-59848/-59849, etc.), and five Elasticsearch vulnerabilities (CVE-2026-56145, -63136, -63140, -63144, -63263, -56144). Libssh/Libssh2 flaws are relevant to any NetApp product bundling SSH client libraries — verify fix availability per product.

Open source
Advisory

CVE-2026-66035 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0004/

NetApp published this interim advisory covering CVE-2026-66035; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-66034 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0003/

NetApp published this interim advisory covering CVE-2026-66034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-66033 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0002/

NetApp published this interim advisory covering CVE-2026-66033; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-66032 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0001/

NetApp published this interim advisory covering CVE-2026-66032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-64531 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0005/

NetApp published this interim advisory covering CVE-2026-64531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63263 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0019/

NetApp published this interim advisory covering CVE-2026-63263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63144 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0018/

NetApp published this interim advisory covering CVE-2026-63144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63140 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0017/

NetApp published this interim advisory covering CVE-2026-63140; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63136 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0016/

NetApp published this interim advisory covering CVE-2026-63136; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59850 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0011/

NetApp published this interim advisory covering CVE-2026-59850; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59849 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0014/

NetApp published this interim advisory covering CVE-2026-59849; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59848 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0013/

NetApp published this interim advisory covering CVE-2026-59848; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59847 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0010/

NetApp published this interim advisory covering CVE-2026-59847; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59846 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0012/

NetApp published this interim advisory covering CVE-2026-59846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59845 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0009/

NetApp published this interim advisory covering CVE-2026-59845; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59844 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0008/

NetApp published this interim advisory covering CVE-2026-59844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-56145 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0015/

NetApp published this interim advisory covering CVE-2026-56145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-56144 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0020/

NetApp published this interim advisory covering CVE-2026-56144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-53655 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0006/

NetApp published this interim advisory covering CVE-2026-53655; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-15370 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0007/

NetApp published this interim advisory covering CVE-2026-15370; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2026 MySQL Server 9.7.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0019/

NetApp published this interim advisory covering CVE-2026-47008, CVE-2026-61144, CVE-2026-61128, CVE-2026-60718, CVE-2026-60194, CVE-2026-61093, CVE-2026-60181, CVE-2026-60324, CVE-2026-61108, CVE-2026-60174, CVE-2026-60195; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2026 MySQL Server 8.4.0 and 9.7.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0017/

NetApp published this interim advisory covering CVE-2026-60332, CVE-2026-61094, CVE-2026-60188, CVE-2026-60163, CVE-2026-47064, CVE-2026-47023, CVE-2026-60331, CVE-2026-46936, CVE-2026-60184, CVE-2026-61096, CVE-2026-61081, CVE-2026-60185, CVE-2026-60187, CVE-2026-60183, CVE-2026-47012, CVE-2026-60189, CVE-2026-47052, CVE-2026-61109, CVE-2026-60315, CVE-2026-60182, CVE-2026-60191, CVE-2026-60190, CVE-2026-60145, CVE-2026-60747, CVE-2026-60177, CVE-2026-60585, CVE-2026-60178, CVE-2026-60316, CVE-2026-60186; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

July 2026 MySQL Connector/J Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0018/

NetApp published this final advisory covering CVE-2026-60624, CVE-2026-61082, CVE-2026-60623, CVE-2026-60586; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-9828 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0012/

NetApp published this interim advisory covering CVE-2026-9828; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-9079 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0004/

NetApp published this interim advisory covering CVE-2026-9079; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-9079 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0004

NetApp published security advisory NTAP-20260731-0004 on 2026-07-31, CVE-2026-9079. Libcurl versions 8.8.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-8927 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0008/

NetApp published this interim advisory covering CVE-2026-8927; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-8926 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0007/

NetApp published this interim advisory covering CVE-2026-8926; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-8925 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0003/

NetApp published this interim advisory covering CVE-2026-8925; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-8925 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0003

NetApp published security advisory NTAP-20260731-0003 on 2026-07-31, CVE-2026-8925. Libcurl versions 8.15.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-8924 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0006/

NetApp published this interim advisory covering CVE-2026-8924; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-60311 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0020/

NetApp published this interim advisory covering CVE-2026-60311; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42505 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0010/

NetApp published this interim advisory covering CVE-2026-42505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-41839 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0014/

NetApp published this interim advisory covering CVE-2026-41839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40993 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0011/

NetApp published this interim advisory covering CVE-2026-40993; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39822 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0009/

NetApp published this interim advisory covering CVE-2026-39822; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33630 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0015/

NetApp published this interim advisory covering CVE-2026-33630; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3276 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0013/

NetApp published this interim advisory covering CVE-2026-3276; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2026-31633 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0001/

NetApp published this interim advisory covering CVE-2026-31633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31633 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0001

NetApp published security advisory NTAP-20260731-0001 on 2026-07-31, CVE-2026-31633. Linux kernel versions 6.16-rc1 through 6.18.22, 6.19-rc1 through 6.19.12, and 6.20-rc1 through 7.0-rc7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-26143 Microsoft PowerShell Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0016/

NetApp published this interim advisory covering CVE-2026-26143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11856 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0002/

NetApp published this interim advisory covering CVE-2026-11856; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11856 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0002

NetApp published security advisory NTAP-20260731-0002 on 2026-07-31, CVE-2026-11856. Libcurl versions 7.10.6 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-11564 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260731-0005/

NetApp published this interim advisory covering CVE-2026-11564; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11564 Libcurl Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260731-0005

NetApp published security advisory NTAP-20260731-0005 on 2026-07-31, CVE-2026-11564. Libcurl versions 8.17.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-13321 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0001/

NetApp published this interim advisory covering CVE-2026-13321; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-13204 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0006/

NetApp published this interim advisory covering CVE-2026-13204; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11721 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0004/

NetApp published this interim advisory covering CVE-2026-11721; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11622 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0007/

NetApp published this interim advisory covering CVE-2026-11622; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11605 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0009/

NetApp published this interim advisory covering CVE-2026-11605; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11331 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0008/

NetApp published this interim advisory covering CVE-2026-11331; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10822 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0003/

NetApp published this interim advisory covering CVE-2026-10822; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10723 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260730-0002/

NetApp published this interim advisory covering CVE-2026-10723; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260730-0010

Source: https://security.netapp.com/advisory/NTAP-20260730-0010/

NetApp security advisory NTAP-20260730-0010. CVEs: CVE-2026-60005. NGINX versions 1.15.8 prior to 1.30.4 and 1.31 prior to 1.31.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260730-0005

Source: https://security.netapp.com/advisory/NTAP-20260730-0005/

NetApp security advisory NTAP-20260730-0005. CVEs: CVE-2026-12617. ISC BIND versions 9.18.0 through 9.18.50 and 9.20.0 through 9.20.24 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

June 2026 Apache Netty 4.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0013/

NetApp published this interim advisory covering CVE-2026-44892, CVE-2026-44894, CVE-2026-48748, CVE-2026-50009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2026 Java Platform Standard Edition 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0016/

NetApp published this interim advisory covering CVE-2026-47059, CVE-2026-47027, CVE-2026-46968, CVE-2026-60147, CVE-2026-47063, CVE-2026-47010, CVE-2026-47021; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

July 2026 Java Platform Standard Edition 8u491, 8u491-perf, 11.0.31 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0017/

NetApp published this interim advisory covering CVE-2026-47057, CVE-2026-47058; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2026 Java Platform Standard Edition 8u491 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0020/

NetApp published this interim advisory covering CVE-2026-60164, CVE-2026-47034, CVE-2026-47013, CVE-2026-47035, CVE-2026-60166, CVE-2026-47030; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-60526 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0018/

NetApp published this interim advisory covering CVE-2026-60526; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58052 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0011/

NetApp published this interim advisory covering CVE-2026-58052; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2026-49844 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0012/

NetApp published this interim advisory covering CVE-2026-49844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46307 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0006/

NetApp published this interim advisory covering CVE-2026-46307; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46306 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0009/

NetApp published this interim advisory covering CVE-2026-46306; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46304 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0008/

NetApp published this interim advisory covering CVE-2026-46304; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46303 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0007/

NetApp published this interim advisory covering CVE-2026-46303; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44432 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0003/

NetApp published this interim advisory covering CVE-2026-44432; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-44431 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0004/

NetApp published this interim advisory covering CVE-2026-44431; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33413 Etcd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0005/

NetApp published this final advisory covering CVE-2026-33413; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-15995 IBM Cognos Analytics Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260724-0014/

NetApp published this final advisory covering CVE-2026-15995; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260724-0010

Source: https://security.netapp.com/advisory/NTAP-20260724-0010/

NetApp security advisory NTAP-20260724-0010. CVEs: CVE-2026-14266. 7-Zip versions prior to 26.02 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260724-0002

Source: https://security.netapp.com/advisory/NTAP-20260724-0002/

NetApp security advisory NTAP-20260724-0002. CVEs: CVE-2026-33845, CVE-2026-33846, CVE-2026-3833. GnuTLS versions prior to 3.8.13 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260724-0001

Source: https://security.netapp.com/advisory/NTAP-20260724-0001/

NetApp security advisory NTAP-20260724-0001. CVEs: CVE-2026-42533. NGINX versions 1.15.8 through 1.30.3 and 1.31 through 1.31.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

July 2026 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0012/

NetApp published this interim advisory covering CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; ONTAP Select Deploy administration utility.

Open source
Advisory

July 2026 IBM Db2 IBM Semeru Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0008/

NetApp published this final advisory covering CVE-2026-22021, CVE-2026-22013, CVE-2026-22007; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-9762 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0003/

NetApp published this final advisory covering CVE-2026-9762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-7771 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0006/

NetApp published this final advisory covering CVE-2026-7771; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6653 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0020/

NetApp published this interim advisory covering CVE-2026-6653; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59084 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0019/

NetApp published this interim advisory covering CVE-2026-59084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59083 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0018/

NetApp published this interim advisory covering CVE-2026-59083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4800 Lodash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0010/

NetApp published this interim advisory covering CVE-2026-4800; the API labels exploitation information as **Public**. The API currently lists affected products as: Storage Manager for ProxMox.

Open source
Advisory

CVE-2026-46333 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0009/

NetApp published this interim advisory covering CVE-2026-46333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-41854 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0017/

NetApp published this interim advisory covering CVE-2026-41854; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-41417 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0004/

NetApp published this final advisory covering CVE-2026-41417; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34479 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0007/

NetApp published this final advisory covering CVE-2026-34479; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1299 CPython Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0014/

NetApp published this interim advisory covering CVE-2026-1299; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-10695 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0002/

NetApp published this final advisory covering CVE-2026-10695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10535 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260717-0005/

NetApp published this final advisory covering CVE-2026-10535; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260717-0016

Source: https://security.netapp.com/advisory/NTAP-20260717-0016/

NetApp security advisory NTAP-20260717-0016. CVEs: CVE-2026-15308. CPython versions prior to 3.15.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260717-0015

Source: https://security.netapp.com/advisory/NTAP-20260717-0015/

NetApp security advisory NTAP-20260717-0015. CVEs: CVE-2026-6100. Certain versions of CPython are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260717-0013

Source: https://security.netapp.com/advisory/NTAP-20260717-0013/

NetApp security advisory NTAP-20260717-0013. CVEs: CVE-2026-27448. pyOpenSSL versions 0.14 prior to 26.0.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260717-0011

Source: https://security.netapp.com/advisory/NTAP-20260717-0011/

NetApp security advisory NTAP-20260717-0011. CVEs: CVE-2026-27135. Nghttp2 versions prior to 1.68.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

June 2026 FreeBSD posixshm Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0009/

NetApp published this final advisory covering CVE-2026-49427, CVE-2026-49428; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD iconv Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0004/

NetApp published this final advisory covering CVE-2026-58081, CVE-2026-58082; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-53359 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0017/

NetApp published this interim advisory covering CVE-2026-53359; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-49426 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0008/

NetApp published this final advisory covering CVE-2026-49426; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49425 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0005/

NetApp published this final advisory covering CVE-2026-49425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49424 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0006/

NetApp published this final advisory covering CVE-2026-49424; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49423 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0007/

NetApp published this final advisory covering CVE-2026-49423; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49422 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0015/

NetApp published this final advisory covering CVE-2026-49422; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49421 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0010/

NetApp published this final advisory covering CVE-2026-49421; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49420 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0011/

NetApp published this final advisory covering CVE-2026-49420; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49419 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0013/

NetApp published this final advisory covering CVE-2026-49419; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49418 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0014/

NetApp published this final advisory covering CVE-2026-49418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49415 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0012/

NetApp published this final advisory covering CVE-2026-49415; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49261 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0016/

NetApp published this interim advisory covering CVE-2026-49261; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46242 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0020/

NetApp published this interim advisory covering CVE-2026-46242; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-43503 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0019/

NetApp published this interim advisory covering CVE-2026-43503; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-43499 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0018/

NetApp published this interim advisory covering CVE-2026-43499; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-40023 Apache Log4cxx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0003/

NetApp published this interim advisory covering CVE-2026-40023; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34478 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260710-0002/

NetApp published this interim advisory covering CVE-2026-34478; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

2026-09-01-ntap-20260710-0001

Source: https://security.netapp.com/advisory/NTAP-20260710-0001/

NetApp security advisory NTAP-20260710-0001. CVEs: CVE-2026-42253, CVE-2026-42588, CVE-2026-45505, CVE-2026-46605, CVE-2026-49157, CVE-2026-49270. Apache ActiveMQ versions prior to 5.19.7 and 6.0.0 prior to 6.2.5 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

October 2025 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0007/

NetApp published this interim advisory covering CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61725; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10.

Open source
Advisory

March 2026 Erlang/OTP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0005/

NetApp published this final advisory covering CVE-2026-23941, CVE-2026-23942, CVE-2026-23943; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

June 2026 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0016/

NetApp published this interim advisory covering CVE-2026-50229, CVE-2026-55956; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2026 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0006/

NetApp published this interim advisory covering CVE-2025-61728, CVE-2025-61730, CVE-2025-61731, CVE-2025-68119; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-55957 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0014/

NetApp published this interim advisory covering CVE-2026-55957; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55955 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0015/

NetApp published this interim advisory covering CVE-2026-55955; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55276 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0018/

NetApp published this interim advisory covering CVE-2026-55276; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-55200 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0020/

NetApp published this interim advisory covering CVE-2026-55200; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-53434 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0013/

NetApp published this interim advisory covering CVE-2026-53434; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-53404 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0017/

NetApp published this interim advisory covering CVE-2026-53404; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46331 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0002/

NetApp published this interim advisory covering CVE-2026-46331; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45491 .Net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0009/

NetApp published this interim advisory covering CVE-2026-45491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45490 .Net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0008/

NetApp published this interim advisory covering CVE-2026-45490; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34481 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0012/

NetApp published this interim advisory covering CVE-2026-34481; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

CVE-2026-34479 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0011/

NetApp published this interim advisory covering CVE-2026-34479; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

CVE-2026-31718 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0001/

NetApp published this interim advisory covering CVE-2026-31718; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15661 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0019/

NetApp published this interim advisory covering CVE-2025-15661; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-24990 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0004/

NetApp published this interim advisory covering CVE-2024-24990; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24989 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260703-0003/

NetApp published this interim advisory covering CVE-2024-24989; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2026 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0019/

NetApp published this interim advisory covering CVE-2026-41417, CVE-2026-42578, CVE-2026-42579, CVE-2026-42580, CVE-2026-42581, CVE-2026-42583, CVE-2026-42584, CVE-2026-42585, CVE-2026-42586, CVE-2026-42587, CVE-2026-44248; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

June 2026 IBM Db2 Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0008/

NetApp published this final advisory covering CVE-2026-33871, CVE-2026-42583, CVE-2026-42580, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, CVE-2026-42587, CVE-2026-33870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 IBM Db2 Bouncy Castle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0006/

NetApp published this final advisory covering CVE-2025-14813, CVE-2026-5598, CVE-2026-5588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 IBM Db2 Apache Log4j Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0009/

NetApp published this final advisory covering CVE-2026-34480, CVE-2026-34477, CVE-2026-34478; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Golang.Org/X/Net Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0012/

NetApp published this interim advisory covering CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502, CVE-2026-42506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD Unbound Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0001/

NetApp published this final advisory covering CVE-2026-32792, CVE-2026-33278, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944, CVE-2026-42959, CVE-2026-42960, CVE-2026-44390, CVE-2026-44608; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 FreeBSD Sound Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0002/

NetApp published this final advisory covering CVE-2026-45258, CVE-2026-49417; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Apache Netty 4.1 and 4.2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0020/

NetApp published this interim advisory covering CVE-2026-44249, CVE-2026-44250, CVE-2026-44890, CVE-2026-44893, CVE-2026-48006, CVE-2026-48043, CVE-2026-48059, CVE-2026-50010, CVE-2026-50011, CVE-2026-50020, CVE-2026-50560, CVE-2026-45416, CVE-2026-45536, CVE-2026-45673, CVE-2026-45674, CVE-2026-46340, CVE-2026-47244, CVE-2026-47691; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49759 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0014/

NetApp published this interim advisory covering CVE-2026-49759; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2026-49413 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0003/

NetApp published this final advisory covering CVE-2026-49413; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46863 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0016/

NetApp published this interim advisory covering CVE-2026-46863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2026-45259 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0005/

NetApp published this final advisory covering CVE-2026-45259; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45256 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0004/

NetApp published this final advisory covering CVE-2026-45256; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40971 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0018/

NetApp published this interim advisory covering CVE-2026-40971; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39827 Golang.Org/X/Crypto Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0013/

NetApp published this interim advisory covering CVE-2026-39827; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28808 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0015/

NetApp published this final advisory covering CVE-2026-28808; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-11906 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0010/

NetApp published this final advisory covering CVE-2026-11906; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10109 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0007/

NetApp published this final advisory covering CVE-2026-10109; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36372 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260626-0011/

NetApp published this final advisory covering CVE-2025-36372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260626-0017

Source: https://security.netapp.com/advisory/NTAP-20260626-0017/

NetApp security advisory NTAP-20260626-0017. CVEs: CVE-2026-2303. Multiple NetApp products incorporate MongoDB Drivers. MongoDB Drivers versions prior to 1.17.7 and 2.0.0-alpha1 prior to 2.4.2 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

CVE-2026-49416 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0019/

NetApp published this final advisory covering CVE-2026-49416; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49414 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0017/

NetApp published this final advisory covering CVE-2026-49414; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-49412 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0018/

NetApp published this final advisory covering CVE-2026-49412; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-48095 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0001/

NetApp published this interim advisory covering CVE-2026-48095; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45257 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0020/

NetApp published this final advisory covering CVE-2026-45257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42501 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0004/

NetApp published this interim advisory covering CVE-2026-42501; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42499 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0003/

NetApp published this interim advisory covering CVE-2026-42499; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39836 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0005/

NetApp published this interim advisory covering CVE-2026-39836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39826 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0007/

NetApp published this interim advisory covering CVE-2026-39826; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39825 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0011/

NetApp published this interim advisory covering CVE-2026-39825; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39823 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0008/

NetApp published this interim advisory covering CVE-2026-39823; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39819 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0010/

NetApp published this interim advisory covering CVE-2026-39819; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39817 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0009/

NetApp published this interim advisory covering CVE-2026-39817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33748 Moby/Buildkit Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0014/

NetApp published this interim advisory covering CVE-2026-33748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33747 Moby/Buildkit Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0013/

NetApp published this interim advisory covering CVE-2026-33747; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27145 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0006/

NetApp published this interim advisory covering CVE-2026-27145; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights Telegraf Agent; NetApp Kubernetes Monitoring Operator; Trident; Trident Protect.

Open source
Advisory

CVE-2026-27139 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0012/

NetApp published this interim advisory covering CVE-2026-27139; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10846 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0016/

NetApp published this final advisory covering CVE-2026-10846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10263 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260619-0015/

NetApp published this final advisory covering CVE-2025-10263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Apache CXF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0004/

NetApp published this interim advisory covering CVE-2026-49875, CVE-2026-50623, CVE-2026-50627, CVE-2026-50628, CVE-2026-50629, CVE-2026-50630, CVE-2026-50631, CVE-2026-50632, CVE-2026-50633, CVE-2026-50634, CVE-2026-50645; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-44930 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0001/

NetApp published this interim advisory covering CVE-2026-44930; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-44618 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0003/

NetApp published this interim advisory covering CVE-2026-44618; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-44417 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0002/

NetApp published this interim advisory covering CVE-2026-44417; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-54988 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260618-0005/

NetApp published this interim advisory covering CVE-2025-54988; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2026 Golang Crypto Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0019/

NetApp published this interim advisory covering CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-46598; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent Container (tp-proxy); Trident Protect; Trident Protect Connector.

Open source
Advisory

CVE-2026-9076 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0008/

NetApp published this interim advisory covering CVE-2026-9076; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-7383 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0003/

NetApp published this interim advisory covering CVE-2026-7383; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45447 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0002/

NetApp published this interim advisory covering CVE-2026-45447; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45446 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0016/

NetApp published this interim advisory covering CVE-2026-45446; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-45445 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0007/

NetApp published this interim advisory covering CVE-2026-45445; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42771 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0011/

NetApp published this interim advisory covering CVE-2026-42771; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42770 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0018/

NetApp published this interim advisory covering CVE-2026-42770; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42769 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0014/

NetApp published this interim advisory covering CVE-2026-42769; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42768 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0017/

NetApp published this interim advisory covering CVE-2026-42768; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42767 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0012/

NetApp published this interim advisory covering CVE-2026-42767; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42766 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0013/

NetApp published this interim advisory covering CVE-2026-42766; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42765 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0005/

NetApp published this interim advisory covering CVE-2026-42765; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-42764 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0004/

NetApp published this interim advisory covering CVE-2026-42764; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-35188 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0015/

NetApp published this interim advisory covering CVE-2026-35188; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34183 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0006/

NetApp published this interim advisory covering CVE-2026-34183; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34182 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0001/

NetApp published this interim advisory covering CVE-2026-34182; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34181 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0010/

NetApp published this interim advisory covering CVE-2026-34181; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-34180 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260617-0009/

NetApp published this interim advisory covering CVE-2026-34180; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-6238 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0002/

NetApp published this interim advisory covering CVE-2026-6238; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-39882 OpenTelemetry-Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0009/

NetApp published this interim advisory covering CVE-2026-39882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39824 Golang.Org/X/Sys Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0007/

NetApp published this final advisory covering CVE-2026-39824; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33814 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0006/

NetApp published this interim advisory covering CVE-2026-33814; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident Protect.

Open source
Advisory

CVE-2026-3184 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0011/

NetApp published this interim advisory covering CVE-2026-3184; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-27456 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0012/

NetApp published this interim advisory covering CVE-2026-27456; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-58187 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0003/

NetApp published this interim advisory covering CVE-2025-58187; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2021-35939 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0016/

NetApp published this interim advisory covering CVE-2021-35939; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35938 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0017/

NetApp published this interim advisory covering CVE-2021-35938; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-35937 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0015/

NetApp published this interim advisory covering CVE-2021-35937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3521 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0018/

NetApp published this interim advisory covering CVE-2021-3521; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3421 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0020/

NetApp published this interim advisory covering CVE-2021-3421; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20266 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0019/

NetApp published this interim advisory covering CVE-2021-20266; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-7501 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0014/

NetApp published this interim advisory covering CVE-2017-7501; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-7500 rpm Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260612-0013/

NetApp published this interim advisory covering CVE-2017-7500; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2026 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0001/

NetApp published this interim advisory covering CVE-2026-29167, CVE-2026-34356, CVE-2026-42536, CVE-2026-43951, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-34355, CVE-2026-44119; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

CVE-2026-48913 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0004/

NetApp published this interim advisory covering CVE-2026-48913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42535 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0002/

NetApp published this interim advisory covering CVE-2026-42535; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34003 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0010/

NetApp published this interim advisory covering CVE-2026-34003; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34002 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0007/

NetApp published this interim advisory covering CVE-2026-34002; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34001 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0009/

NetApp published this interim advisory covering CVE-2026-34001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34000 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0006/

NetApp published this interim advisory covering CVE-2026-34000; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33999 X.Org Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0008/

NetApp published this interim advisory covering CVE-2026-33999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29170 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260610-0005/

NetApp published this interim advisory covering CVE-2026-29170; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-48710 Starlette Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0011/

NetApp published this interim advisory covering CVE-2026-48710; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-43501 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0015/

NetApp published this interim advisory covering CVE-2026-43501; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42790 Erlang/OTP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0010/

NetApp published this interim advisory covering CVE-2026-42790; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; SnapCenter.

Open source
Advisory

CVE-2026-40977 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0009/

NetApp published this interim advisory covering CVE-2026-40977; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

CVE-2026-35554 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0008/

NetApp published this interim advisory covering CVE-2026-35554; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31607 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0014/

NetApp published this interim advisory covering CVE-2026-31607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24281 Apache Zookeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0007/

NetApp published this interim advisory covering CVE-2026-24281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7345 GDK-Pixbuf Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0006/

NetApp published this final advisory covering CVE-2025-7345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-41244 VMware Tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0005/

NetApp published this interim advisory covering CVE-2025-41244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15284 Qs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0004/

NetApp published this interim advisory covering CVE-2025-15284; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14512 GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0003/

NetApp published this interim advisory covering CVE-2025-14512; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-14087 GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0002/

NetApp published this interim advisory covering CVE-2025-14087; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-57699 Json-smart Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0001/

NetApp published this final advisory covering CVE-2024-57699; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 Spring Boot Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260605-0013/

NetApp published this interim advisory covering CVE-2026-40972, CVE-2026-40973, CVE-2026-40974, CVE-2026-40975; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

2026-09-01-ntap-20260605-0012

Source: https://security.netapp.com/advisory/NTAP-20260605-0012/

NetApp security advisory NTAP-20260605-0012. CVEs: CVE-2026-9256. Multiple NetApp products incorporate NGINX. NGINX versions prior to 1.30.2 and 1.31.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

May 2026 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0014/

NetApp published this interim advisory covering CVE-2026-41284, CVE-2026-41293, CVE-2026-43512, CVE-2026-43513, CVE-2026-43514, CVE-2026-43515; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6938 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0009/

NetApp published this final advisory covering CVE-2026-6938; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6053 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0011/

NetApp published this final advisory covering CVE-2026-6053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6052 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0008/

NetApp published this final advisory covering CVE-2026-6052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6051 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0012/

NetApp published this final advisory covering CVE-2026-6051; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-5950 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0006/

NetApp published this interim advisory covering CVE-2026-5950; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-5947 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0003/

NetApp published this interim advisory covering CVE-2026-5947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-5946 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0002/

NetApp published this interim advisory covering CVE-2026-5946; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP 9.

Open source
Advisory

CVE-2026-44578 Next.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0013/

NetApp published this interim advisory covering CVE-2026-44578; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3593 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0004/

NetApp published this interim advisory covering CVE-2026-3593; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3592 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0005/

NetApp published this interim advisory covering CVE-2026-3592; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-3039 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0001/

NetApp published this interim advisory covering CVE-2026-3039; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2026-1718 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0007/

NetApp published this final advisory covering CVE-2026-1718; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-13755 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0010/

NetApp published this final advisory covering CVE-2025-13755; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 Apache Thrift Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260529-0015/

NetApp published this interim advisory covering CVE-2025-48431, CVE-2026-41602, CVE-2026-41603, CVE-2026-41604, CVE-2026-41605, CVE-2026-41606, CVE-2026-41607, CVE-2026-41636, CVE-2026-43868, CVE-2026-43869, CVE-2026-43870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45255 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0011/

NetApp published this final advisory covering CVE-2026-45255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45254 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0012/

NetApp published this final advisory covering CVE-2026-45254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45253 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0008/

NetApp published this final advisory covering CVE-2026-45253; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45252 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0013/

NetApp published this final advisory covering CVE-2026-45252; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45251 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0010/

NetApp published this final advisory covering CVE-2026-45251; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45250 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0009/

NetApp published this final advisory covering CVE-2026-45250; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4480 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0002/

NetApp published this interim advisory covering CVE-2026-4480; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39461 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0007/

NetApp published this final advisory covering CVE-2026-39461; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3238 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0004/

NetApp published this final advisory covering CVE-2026-3238; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3012 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0003/

NetApp published this final advisory covering CVE-2026-3012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-2340 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0006/

NetApp published this final advisory covering CVE-2026-2340; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1933 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0005/

NetApp published this final advisory covering CVE-2026-1933; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-1000405 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260527-0014/

NetApp published this interim advisory covering CVE-2017-1000405; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; E-Series SANtricity OS Controller Software; NetApp Cloud Backup (formerly AltaVault); NetApp VASA Provider for Clustered Data ONTAP 6.x; ONTAP Select Deploy administration utility; OnCommand Balance; SnapProtect; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

2026-09-01-ntap-20260527-0001

Source: https://security.netapp.com/advisory/NTAP-20260527-0001/

NetApp security advisory NTAP-20260527-0001. CVEs: CVE-2026-4408. Samba versions prior to 4.22.10, 4.23.8 and 4.24.3 are susceptible to a vulnerability which when successfully exploited could lead to unauthenticated Remote Code Execution.

Open source
Advisory

May 2026 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0001/

NetApp published this interim advisory covering CVE-2025-27516, CVE-2025-50059, CVE-2025-50106, CVE-2025-30749, CVE-2025-30761, CVE-2025-30754, CVE-2025-30167, CVE-2024-56339, CVE-2025-48976, CVE-2025-3633, CVE-2025-53057, CVE-2025-53066, CVE-2024-12798, CVE-2024-12801, CVE-2025-36126, CVE-2024-6844, CVE-2024-6839, CVE-2024-6866, CVE-2025-6020, CVE-2025-21587, CVE-2025-30698, CVE-2025-2900, CVE-2025-4447, CVE-2024-5535, CVE-2025-5889, CVE-2024-35195, CVE-2025-7962, CVE-2025-54798, CVE-2025-50181, CVE-2025-50182, CVE-2025-68146, CVE-2025-56200; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2026-42946 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0012/

NetApp published this interim advisory covering CVE-2026-42946; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42934 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0014/

NetApp published this interim advisory covering CVE-2026-42934; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-42498 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0010/

NetApp published this interim advisory covering CVE-2026-42498; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40701 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0013/

NetApp published this interim advisory covering CVE-2026-40701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40021 Apache Log4Net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0002/

NetApp published this interim advisory covering CVE-2026-40021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34500 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0006/

NetApp published this interim advisory covering CVE-2026-34500; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34487 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0007/

NetApp published this interim advisory covering CVE-2026-34487; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34486 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0009/

NetApp published this interim advisory covering CVE-2026-34486; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34483 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0008/

NetApp published this interim advisory covering CVE-2026-34483; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-32990 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0005/

NetApp published this interim advisory covering CVE-2026-32990; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29145 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0003/

NetApp published this interim advisory covering CVE-2026-29145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-25854 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0004/

NetApp published this interim advisory covering CVE-2026-25854; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-30185 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0019/

NetApp published this interim advisory covering CVE-2025-30185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27560 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0020/

NetApp published this interim advisory covering CVE-2025-27560; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20077 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0018/

NetApp published this interim advisory covering CVE-2025-20077; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6200 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0017/

NetApp published this interim advisory covering CVE-2023-6200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-1000253 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260522-0015/

NetApp published this interim advisory covering CVE-2017-1000253; the API labels exploitation information as **Public**. The API currently lists affected products as: Data ONTAP Edge; NetApp Cloud Backup (formerly AltaVault); OnCommand Balance; SnapProtect.

Open source
Advisory

2026-09-01-ntap-20260522-0016

Source: https://security.netapp.com/advisory/NTAP-20260522-0016/

NetApp security advisory NTAP-20260522-0016. CVEs: CVE-2026-46300. Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a local privilege escalation vulnerability referred to as Fragnesia that could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260522-0011

Source: https://security.netapp.com/advisory/NTAP-20260522-0011/

NetApp security advisory NTAP-20260522-0011. CVEs: CVE-2026-42945. Multiple NetApp products incorporate NGINX. NGINX versions 0.6.27 through 0.9.7 and 1.0.0 through 1.30.0 are susceptible to a vulnerability referred to as NGINX Rift which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-7168 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0008/

NetApp published this interim advisory covering CVE-2026-7168; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-7009 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0007/

NetApp published this interim advisory covering CVE-2026-7009; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-6429 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0003/

NetApp published this interim advisory covering CVE-2026-6429; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-6276 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0009/

NetApp published this interim advisory covering CVE-2026-6276; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-6253 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0006/

NetApp published this interim advisory covering CVE-2026-6253; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-5773 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0004/

NetApp published this interim advisory covering CVE-2026-5773; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-5545 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0005/

NetApp published this interim advisory covering CVE-2026-5545; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-2006 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0002/

NetApp published this interim advisory covering CVE-2026-2006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-2005 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260515-0001/

NetApp published this interim advisory covering CVE-2026-2005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260515-0010

Source: https://security.netapp.com/advisory/NTAP-20260515-0010/

NetApp security advisory NTAP-20260515-0010. CVEs: CVE-2026-2391. Multiple NetApp products incorporate qs. Qs versions 6.7.0 through 6.14.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-5450 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0006/

NetApp published this interim advisory covering CVE-2026-5450; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-5435 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0005/

NetApp published this interim advisory covering CVE-2026-5435; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-43500 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0002/

NetApp published this interim advisory covering CVE-2026-43500; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-43284 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0001/

NetApp published this interim advisory covering CVE-2026-43284; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-35469 Spdystream Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0009/

NetApp published this final advisory covering CVE-2026-35469; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34480 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0007/

NetApp published this interim advisory covering CVE-2026-34480; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34477 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0008/

NetApp published this interim advisory covering CVE-2026-34477; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29181 Opentelemetry-Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0010/

NetApp published this interim advisory covering CVE-2026-29181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36899 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260513-0003/

NetApp published this interim advisory covering CVE-2024-36899; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34059 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0010/

NetApp published this final advisory covering CVE-2026-34059; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34032 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0016/

NetApp published this final advisory covering CVE-2026-34032; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33857 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0015/

NetApp published this final advisory covering CVE-2026-33857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33523 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0012/

NetApp published this final advisory covering CVE-2026-33523; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33007 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0014/

NetApp published this final advisory covering CVE-2026-33007; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33006 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0017/

NetApp published this final advisory covering CVE-2026-33006; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29169 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0009/

NetApp published this final advisory covering CVE-2026-29169; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-29168 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0011/

NetApp published this final advisory covering CVE-2026-29168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28780 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0007/

NetApp published this final advisory covering CVE-2026-28780; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27137 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0020/

NetApp published this interim advisory covering CVE-2026-27137; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-24308 Apache Zookeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0019/

NetApp published this interim advisory covering CVE-2026-24308; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24072 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0013/

NetApp published this final advisory covering CVE-2026-24072; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-23918 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0008/

NetApp published this final advisory covering CVE-2026-23918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-23003 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0004/

NetApp published this interim advisory covering CVE-2026-23003; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22997 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0003/

NetApp published this interim advisory covering CVE-2026-22997; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22992 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0005/

NetApp published this interim advisory covering CVE-2026-22992; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-22991 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0006/

NetApp published this interim advisory covering CVE-2026-22991; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-0603 Hibernate ORM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260508-0018/

NetApp published this interim advisory covering CVE-2026-0603; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

2026-09-01-ntap-20260508-0002

Source: https://security.netapp.com/advisory/NTAP-20260508-0002/

NetApp security advisory NTAP-20260508-0002. CVEs: CVE-2026-22990. Multiple NetApp products incorporate Linux kernel. Linux kernel versions through 5.10.247, 5.11-rc1 through 5.15.197, 5.16-rc1 through 6.1.160, 6.13-rc1 through 6.18.5, 6.19-rc1 through 6.19-rc4, 6.2-rc1 through 6.6.120 and 6.7-rc1 through 6.12.65 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260508-0001

Source: https://security.netapp.com/advisory/NTAP-20260508-0001/

NetApp security advisory NTAP-20260508-0001. CVEs: CVE-2026-22984. Multiple NetApp products incorporate Linux kernel. Linux kernel versions through 5.15.197, 5.16-rc1 through 6.1.160, 6.13-rc1 through 6.18.5, 6.19-rc1 through 6.19-rc4, 6.2-rc1 through 6.6.120 and 6.7-rc1 through 6.12.65 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS).

Open source
Advisory

February 2026 Libssh Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0015/

NetApp published this interim advisory covering CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-7270 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0003/

NetApp published this final advisory covering CVE-2026-7270; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-7164 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0007/

NetApp published this final advisory covering CVE-2026-7164; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-39457 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0004/

NetApp published this final advisory covering CVE-2026-39457; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33228 Flatted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0008/

NetApp published this interim advisory covering CVE-2026-33228; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31431 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0001/

NetApp published this interim advisory covering CVE-2026-31431; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28367 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0009/

NetApp published this final advisory covering CVE-2026-28367; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22732 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0013/

NetApp published this interim advisory covering CVE-2026-22732; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-20096 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260501-0012/

NetApp published this interim advisory covering CVE-2025-20096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6386 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0014/

NetApp published this final advisory covering CVE-2026-6386; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-5398 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0013/

NetApp published this final advisory covering CVE-2026-5398; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-40372 ASP.NET Core Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0003/

NetApp published this final advisory covering CVE-2026-40372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22008 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0008/

NetApp published this interim advisory covering CVE-2026-22008; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22003 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0009/

NetApp published this interim advisory covering CVE-2026-22003; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-20652 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0010/

NetApp published this interim advisory covering CVE-2026-20652; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-69277 Libsodium Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0015/

NetApp published this interim advisory covering CVE-2025-69277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-46836 net-tools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0002/

NetApp published this final advisory covering CVE-2025-46836; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-20916 Pip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0001/

NetApp published this interim advisory covering CVE-2019-20916; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 MySQL Server 9.0.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0006/

NetApp published this interim advisory covering CVE-2026-35234, CVE-2026-35235, CVE-2026-34272; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 MySQL Server 8.0.0, 8.4.0 and 9.0.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0005/

NetApp published this interim advisory covering CVE-2026-35237, CVE-2026-21998, CVE-2026-35236, CVE-2026-34303, CVE-2026-35240, CVE-2026-35238, CVE-2026-35239, CVE-2026-22015, CVE-2026-22009, CVE-2026-22017, CVE-2026-22004, CVE-2026-34270, CVE-2026-34276, CVE-2026-34308, CVE-2026-22001, CVE-2025-14017, CVE-2026-22002, CVE-2026-34271, CVE-2026-22005, CVE-2025-15467, CVE-2026-34304; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

April 2026 MySQL Server 8.0.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260429-0004/

NetApp published this interim advisory covering CVE-2026-34267, CVE-2026-34278, CVE-2026-34293; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

2026-09-01-ntap-20260429-0012

Source: https://security.netapp.com/advisory/NTAP-20260429-0012/

NetApp security advisory NTAP-20260429-0012. CVEs: CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268. Multiple NetApp products incorporate Java SE. Java SE versions 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2 and 26 are susceptible to a vulnerability that could allow unauthenticated attacker with network access via HTTPS or multiple protocols or with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker for CVE-2026-22013. Refer to “Oracle Critical Patch Update

Open source
Advisory

2026-09-01-ntap-20260429-0011

Source: https://security.netapp.com/advisory/NTAP-20260429-0011/

NetApp security advisory NTAP-20260429-0011. CVEs: CVE-2026-34282. Multiple NetApp products incorporate Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2 and 26 are susceptible to a vulnerability which when successfully exploited could allow unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - April 2026” for additional details.

Open source
Advisory

CVE-2026-5704 Tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0010/

NetApp published this interim advisory covering CVE-2026-5704; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (cbs_catalog); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-35388 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0006/

NetApp published this interim advisory covering CVE-2026-35388; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-35387 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0005/

NetApp published this interim advisory covering CVE-2026-35387; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

CVE-2026-35386 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0004/

NetApp published this interim advisory covering CVE-2026-35386; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

CVE-2026-32772 GNU Inetutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0009/

NetApp published this final advisory covering CVE-2026-32772; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27699 Basic-ftp Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0008/

NetApp published this final advisory covering CVE-2026-27699; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22998 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0019/

NetApp published this interim advisory covering CVE-2026-22998; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-68263 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0012/

NetApp published this interim advisory covering CVE-2025-68263; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-64756 Node-Glob Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0007/

NetApp published this final advisory covering CVE-2025-64756; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-37924 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0011/

NetApp published this interim advisory covering CVE-2025-37924; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

April 2026 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260424-0001/

NetApp published this interim advisory covering CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; ONTAP tools for VMware vSphere 10; Trident; Trident Protect.

Open source
Advisory

2026-09-01-ntap-20260424-0020

Source: https://security.netapp.com/advisory/NTAP-20260424-0020/

NetApp security advisory NTAP-20260424-0020. CVEs: CVE-2026-23095. Multiple NetApp products incorporate Linux Kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-39865 Axios Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0002/

NetApp published this interim advisory covering CVE-2026-39865; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Shift Toolkit; Storage Manager for ProxMox.

Open source
Advisory

CVE-2026-3676 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0008/

NetApp published this final advisory covering CVE-2026-3676; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33186 gRPC-Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0005/

NetApp published this interim advisory covering CVE-2026-33186; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-33056 Tar-rs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0017/

NetApp published this interim advisory covering CVE-2026-33056; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (cbs_catalog); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-32746 GNU Inetutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0004/

NetApp published this final advisory covering CVE-2026-32746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27142 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0006/

NetApp published this interim advisory covering CVE-2026-27142; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-25679 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0007/

NetApp published this interim advisory covering CVE-2026-25679; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Kubernetes Monitoring Operator; ONTAP tools for VMware vSphere 10; Trident; Trident Protect.

Open source
Advisory

CVE-2026-1577 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0009/

NetApp published this final advisory covering CVE-2026-1577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1352 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0014/

NetApp published this final advisory covering CVE-2026-1352; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68161 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0013/

NetApp published this final advisory covering CVE-2025-68161; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-67735 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0011/

NetApp published this final advisory covering CVE-2025-67735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66168 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0001/

NetApp published this final advisory covering CVE-2025-66168; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-64118 Node-tar Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0019/

NetApp published this interim advisory covering CVE-2025-64118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (cbs_catalog); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-55315 ASP.NET Core Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0020/

NetApp published this final advisory covering CVE-2025-55315; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36122 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0012/

NetApp published this final advisory covering CVE-2025-36122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14688 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0015/

NetApp published this final advisory covering CVE-2025-14688; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-12183 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0010/

NetApp published this final advisory covering CVE-2025-12183; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-58251 BusyBox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260422-0016/

NetApp published this interim advisory covering CVE-2024-58251; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

2026-09-01-ntap-20260422-0018

Source: https://security.netapp.com/advisory/NTAP-20260422-0018/

NetApp security advisory NTAP-20260422-0018. CVEs: CVE-2026-24842. Multiple NetApp products incorporate node-tar. Node-tar versions prior to 7.5.7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260422-0003

Source: https://security.netapp.com/advisory/NTAP-20260422-0003/

NetApp security advisory NTAP-20260422-0003. CVEs: CVE-2026-4046. Multiple NetApp products incorporate GNU C Library (glibc). Glibc versions through 2.43 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-4748 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0006/

NetApp published this final advisory covering CVE-2026-4748; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4652 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0004/

NetApp published this final advisory covering CVE-2026-4652; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-4426 Libarchive Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0007/

NetApp published this interim advisory covering CVE-2026-4426; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp LOADER 8.x.

Open source
Advisory

CVE-2026-4247 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0005/

NetApp published this final advisory covering CVE-2026-4247; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-35414 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0019/

NetApp published this interim advisory covering CVE-2026-35414; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-35385 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0018/

NetApp published this interim advisory covering CVE-2026-35385; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-33227 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0002/

NetApp published this final advisory covering CVE-2026-33227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-28386 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0016/

NetApp published this interim advisory covering CVE-2026-28386; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-65945 Auth0/node-jws Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0009/

NetApp published this interim advisory covering CVE-2025-65945; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2026 Axios Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260417-0020/

NetApp published this interim advisory covering CVE-2025-62718, CVE-2026-40175; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Shift Toolkit; Storage Manager for ProxMox.

Open source
Advisory

2026-09-01-ntap-20260417-0017

Source: https://security.netapp.com/advisory/NTAP-20260417-0017/

NetApp security advisory NTAP-20260417-0017. CVEs: CVE-2026-31790. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information.

Open source
Advisory

2026-09-01-ntap-20260417-0015

Source: https://security.netapp.com/advisory/NTAP-20260417-0015/

NetApp security advisory NTAP-20260417-0015. CVEs: CVE-2026-28387. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0014

Source: https://security.netapp.com/advisory/NTAP-20260417-0014/

NetApp security advisory NTAP-20260417-0014. CVEs: CVE-2026-28388. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0013

Source: https://security.netapp.com/advisory/NTAP-20260417-0013/

NetApp security advisory NTAP-20260417-0013. CVEs: CVE-2026-28389. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0012

Source: https://security.netapp.com/advisory/NTAP-20260417-0012/

NetApp security advisory NTAP-20260417-0012. CVEs: CVE-2026-28390. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0011

Source: https://security.netapp.com/advisory/NTAP-20260417-0011/

NetApp security advisory NTAP-20260417-0011. CVEs: CVE-2026-31789. Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0010

Source: https://security.netapp.com/advisory/NTAP-20260417-0010/

NetApp security advisory NTAP-20260417-0010. CVEs: CVE-2026-32597. Multiple NetApp products incorporate PyJWT. PyJWT versions prior to 2.12.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260417-0008

Source: https://security.netapp.com/advisory/NTAP-20260417-0008/

NetApp security advisory NTAP-20260417-0008. CVEs: CVE-2026-31402. Multiple NetApp products incorporate Linux kernel. Certain Linux kernel versions are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0003

Source: https://security.netapp.com/advisory/NTAP-20260417-0003/

NetApp security advisory NTAP-20260417-0003. CVEs: CVE-2026-23950. Multiple NetApp products incorporate Node-Tar. Node-Tar versions through 7.5.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260417-0001

Source: https://security.netapp.com/advisory/NTAP-20260417-0001/

NetApp security advisory NTAP-20260417-0001. CVEs: CVE-2026-34197. Multiple NetApp products incorporate Apache ActiveMQ. Apache ActiveMQ versions prior to 5.19.4 and 6.0.0 prior to 6.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

March 2026 GNU C Library (glibc) Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0017/

NetApp published this interim advisory covering CVE-2026-4437, CVE-2026-4438; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2026-4747 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0014/

NetApp published this final advisory covering CVE-2026-4747; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-33937 Handlebars.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0005/

NetApp published this interim advisory covering CVE-2026-33937; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-21717 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0011/

NetApp published this interim advisory covering CVE-2026-21717; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-21712 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0010/

NetApp published this interim advisory covering CVE-2026-21712; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1188 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0015/

NetApp published this final advisory covering CVE-2026-1188; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14505 Elliptic Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0016/

NetApp published this interim advisory covering CVE-2025-14505; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-28842 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0002/

NetApp published this interim advisory covering CVE-2023-28842; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28841 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0003/

NetApp published this interim advisory covering CVE-2023-28841; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28840 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260410-0004/

NetApp published this interim advisory covering CVE-2023-28840; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

2026-09-01-ntap-20260410-0020

Source: https://security.netapp.com/advisory/NTAP-20260410-0020/

NetApp security advisory NTAP-20260410-0020. CVEs: CVE-2026-3644. Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260410-0019

Source: https://security.netapp.com/advisory/NTAP-20260410-0019/

NetApp security advisory NTAP-20260410-0019. CVEs: CVE-2026-4519. Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260410-0013

Source: https://security.netapp.com/advisory/NTAP-20260410-0013/

NetApp security advisory NTAP-20260410-0013. CVEs: CVE-2026-21710. Multiple NetApp products incorporate Node.js. All Node.js HTTP servers on 20.x, 22.x, 24.x, and 25.x are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0012

Source: https://security.netapp.com/advisory/NTAP-20260410-0012/

NetApp security advisory NTAP-20260410-0012. CVEs: CVE-2026-21714. Multiple NetApp products incorporate Node.js. Node.js versions 20.x, 22.x, 24.x, and 25.x are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0009

Source: https://security.netapp.com/advisory/NTAP-20260410-0009/

NetApp security advisory NTAP-20260410-0009. CVEs: CVE-2026-33938. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0008

Source: https://security.netapp.com/advisory/NTAP-20260410-0008/

NetApp security advisory NTAP-20260410-0008. CVEs: CVE-2026-33939. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0007

Source: https://security.netapp.com/advisory/NTAP-20260410-0007/

NetApp security advisory NTAP-20260410-0007. CVEs: CVE-2026-33940. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260410-0006

Source: https://security.netapp.com/advisory/NTAP-20260410-0006/

NetApp security advisory NTAP-20260410-0006. CVEs: CVE-2026-33941. Multiple NetApp products incorporate Handlebars.js. Handlebars.js versions 4.0.0 through 4.7.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

Intel SA-01244 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0009/

NetApp published this interim advisory covering CVE-2025-20103, CVE-2025-20054; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3591 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0001/

NetApp published this interim advisory covering CVE-2026-3591; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3260 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0015/

NetApp published this final advisory covering CVE-2026-3260; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3119 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0002/

NetApp published this interim advisory covering CVE-2026-3119; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3104 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0004/

NetApp published this interim advisory covering CVE-2026-3104; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1519 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0003/

NetApp published this final advisory covering CVE-2026-1519; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20100 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0010/

NetApp published this interim advisory covering CVE-2025-20100; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20044 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0014/

NetApp published this interim advisory covering CVE-2025-20044; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20004 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0011/

NetApp published this interim advisory covering CVE-2025-20004; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-48869 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0012/

NetApp published this interim advisory covering CVE-2024-48869; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45332 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0008/

NetApp published this interim advisory covering CVE-2024-45332; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33607 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0013/

NetApp published this interim advisory covering CVE-2024-33607; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22365 Linux-Pam Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260403-0007/

NetApp published this interim advisory covering CVE-2024-22365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-3805 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0001/

NetApp published this interim advisory covering CVE-2026-3805; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2026-3784 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0003/

NetApp published this interim advisory covering CVE-2026-3784; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-3783 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0004/

NetApp published this interim advisory covering CVE-2026-3783; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9.

Open source
Advisory

CVE-2026-1965 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0002/

NetApp published this interim advisory covering CVE-2026-1965; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-58060 CUPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0009/

NetApp published this final advisory covering CVE-2025-58060; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-57347 Node.js dagre-d3-es Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0008/

NetApp published this final advisory covering CVE-2025-57347; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48795 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0014/

NetApp published this interim advisory covering CVE-2025-48795; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; SnapCenter.

Open source
Advisory

CVE-2025-46394 BusyBox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0010/

NetApp published this interim advisory covering CVE-2025-46394; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-15224 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0005/

NetApp published this interim advisory covering CVE-2025-15224; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-13034 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0006/

NetApp published this interim advisory covering CVE-2025-13034; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-11234 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0015/

NetApp published this final advisory covering CVE-2025-11234; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-22898 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260327-0007/

NetApp published this interim advisory covering CVE-2021-22898; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

2026-09-01-ntap-20260327-0011

Source: https://security.netapp.com/advisory/NTAP-20260327-0011/

NetApp security advisory NTAP-20260327-0011. CVEs: CVE-2026-23949. Multiple NetApp products incorporate Jaraco.Context. Jaraco.context versions 5.2.0 prior to 6.1.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information.

Open source
Advisory

December 2025 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0007/

NetApp published this final advisory covering CVE-2025-55130, CVE-2025-55132, CVE-2025-59465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27446 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0011/

NetApp published this final advisory covering CVE-2026-27446; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-2673 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0015/

NetApp published this interim advisory covering CVE-2026-2673; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-25749 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0010/

NetApp published this interim advisory covering CVE-2026-25749; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1489 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0002/

NetApp published this interim advisory covering CVE-2026-1489; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-0988 GLib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0004/

NetApp published this interim advisory covering CVE-2026-0988; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-9714 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0006/

NetApp published this interim advisory covering CVE-2025-9714; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-55131 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0008/

NetApp published this final advisory covering CVE-2025-55131; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-43590 Visual Studio Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0009/

NetApp published this final advisory covering CVE-2024-43590; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41409 PCRE2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260320-0014/

NetApp published this interim advisory covering CVE-2022-41409; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

2026-09-01-ntap-20260320-0013

Source: https://security.netapp.com/advisory/NTAP-20260320-0013/

NetApp security advisory NTAP-20260320-0013. CVEs: CVE-2026-23231. Multiple NetApp products incorporate Linux kernel. Certain versions of linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0012

Source: https://security.netapp.com/advisory/NTAP-20260320-0012/

NetApp security advisory NTAP-20260320-0012. CVEs: CVE-2026-27141. Multiple NetApp products incorporate Golang. golang.org/x/net/http2 versions 0.50.0 prior to 0.51.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0005

Source: https://security.netapp.com/advisory/NTAP-20260320-0005/

NetApp security advisory NTAP-20260320-0005. CVEs: CVE-2026-0861. Multiple NetApp products incorporate GNU C. GNU C Library (aka glibc) versions 2.30 through 2.42 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0003

Source: https://security.netapp.com/advisory/NTAP-20260320-0003/

NetApp security advisory NTAP-20260320-0003. CVEs: CVE-2026-1484. Multiple NetApp products incorporate GLib. GLib versions 2.87.0 through 2.87.3 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260320-0001

Source: https://security.netapp.com/advisory/NTAP-20260320-0001/

NetApp security advisory NTAP-20260320-0001. CVEs: CVE-2026-1485. Multiple NetApp products incorporate GLib. GLib versions through 2.86.3 and 2.87.0 through 2.87.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

Intel SA-01315 Intel AMT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0015/

NetApp published this interim advisory covering CVE-2025-32008, CVE-2025-20080; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1642 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0008/

NetApp published this interim advisory covering CVE-2026-1642; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2026-0915 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0003/

NetApp published this interim advisory covering CVE-2026-0915; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-68372 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0007/

NetApp published this interim advisory covering CVE-2025-68372; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-5702 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0002/

NetApp published this interim advisory covering CVE-2025-5702; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-41117 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0006/

NetApp published this final advisory covering CVE-2025-41117; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27708 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0013/

NetApp published this interim advisory covering CVE-2025-27708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15281 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0001/

NetApp published this interim advisory covering CVE-2025-15281; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-14104 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0012/

NetApp published this interim advisory covering CVE-2025-14104; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11413 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260313-0011/

NetApp published this interim advisory covering CVE-2025-11413; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260313-0010

Source: https://security.netapp.com/advisory/NTAP-20260313-0010/

NetApp security advisory NTAP-20260313-0010. CVEs: CVE-2026-25639. Multiple NetApp products incorporate Axios. Axios versions prior to 0.30.3 prior and to 1.13.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260313-0009

Source: https://security.netapp.com/advisory/NTAP-20260313-0009/

NetApp security advisory NTAP-20260313-0009. CVEs: CVE-2026-21637. Multiple NetApp products incorporate Node.js. Certain versions of Node.js are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

Intel SA-01397 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0003/

NetApp published this interim advisory covering CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467, CVE-2025-27572, CVE-2025-27940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-27171 Zlib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0015/

NetApp published this interim advisory covering CVE-2026-27171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI; NetApp LOADER 8.x; Trident.

Open source
Advisory

CVE-2026-26278 Fast-xml-parser Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0007/

NetApp published this interim advisory covering CVE-2026-26278; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-25896 Fast-xml-parser Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0006/

NetApp published this interim advisory covering CVE-2026-25896; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-21636 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0014/

NetApp published this final advisory covering CVE-2026-21636; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61726 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0009/

NetApp published this interim advisory covering CVE-2025-61726; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident Protect.

Open source
Advisory

CVE-2025-59466 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0011/

NetApp published this final advisory covering CVE-2025-59466; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-59464 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0012/

NetApp published this final advisory covering CVE-2025-59464; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58190 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0008/

NetApp published this interim advisory covering CVE-2025-58190; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident Protect.

Open source
Advisory

CVE-2025-31648 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0002/

NetApp published this interim advisory covering CVE-2025-31648; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23166 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0013/

NetApp published this final advisory covering CVE-2025-23166; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22885 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260311-0004/

NetApp published this interim advisory covering CVE-2025-22885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260311-0010

Source: https://security.netapp.com/advisory/NTAP-20260311-0010/

NetApp security advisory NTAP-20260311-0010. CVEs: CVE-2026-26007. Multiple NetApp products incorporate pyca/cryptography. Cryptography versions prior to 46.0.5 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information.

Open source
Advisory

2026-09-01-ntap-20260311-0001

Source: https://security.netapp.com/advisory/NTAP-20260311-0001/

NetApp security advisory NTAP-20260311-0001. CVEs: CVE-2026-22610. Multiple NetApp products incorporate Angular. Angular versions prior to 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

February 2026 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0001/

NetApp published this final advisory covering CVE-2025-13473, CVE-2025-14550, CVE-2026-1207, CVE-2026-1285, CVE-2026-1287, CVE-2026-1312; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-26158 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0007/

NetApp published this interim advisory covering CVE-2026-26158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-26157 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0006/

NetApp published this interim advisory covering CVE-2026-26157; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-23016 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0019/

NetApp published this interim advisory covering CVE-2026-23016; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-1225 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0008/

NetApp published this interim advisory covering CVE-2026-1225; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; SnapCenter.

Open source
Advisory

CVE-2026-0865 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0014/

NetApp published this interim advisory covering CVE-2026-0865; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-9820 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0016/

NetApp published this interim advisory covering CVE-2025-9820; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-37731 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0005/

NetApp published this final advisory covering CVE-2025-37731; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36428 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0004/

NetApp published this final advisory covering CVE-2025-36428; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36353 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0003/

NetApp published this final advisory covering CVE-2025-36353; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2534 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0002/

NetApp published this final advisory covering CVE-2025-2534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15367 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0013/

NetApp published this interim advisory covering CVE-2025-15367; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15366 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0012/

NetApp published this interim advisory covering CVE-2025-15366; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15282 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0011/

NetApp published this interim advisory covering CVE-2025-15282; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14831 GnuTLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0015/

NetApp published this interim advisory covering CVE-2025-14831; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-12781 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0010/

NetApp published this interim advisory covering CVE-2025-12781; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-11468 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260305-0009/

NetApp published this interim advisory covering CVE-2025-11468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260305-0018

Source: https://security.netapp.com/advisory/NTAP-20260305-0018/

NetApp security advisory NTAP-20260305-0018. CVEs: CVE-2026-23001. Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260305-0017

Source: https://security.netapp.com/advisory/NTAP-20260305-0017/

NetApp security advisory NTAP-20260305-0017. CVEs: CVE-2026-22988. Multiple NetApp products incorporate Linux kernel. Certain versions of Linux Kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2026-24734 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0003/

NetApp published this final advisory covering CVE-2026-24734; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24733 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0002/

NetApp published this interim advisory covering CVE-2026-24733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8191 Swagger UI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0011/

NetApp published this interim advisory covering CVE-2025-8191; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent).

Open source
Advisory

CVE-2025-66614 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0001/

NetApp published this interim advisory covering CVE-2025-66614; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66516 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0004/

NetApp published this interim advisory covering CVE-2025-66516; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36425 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0015/

NetApp published this final advisory covering CVE-2025-36425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36247 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0012/

NetApp published this final advisory covering CVE-2025-36247; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14689 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0014/

NetApp published this final advisory covering CVE-2025-14689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-13867 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0013/

NetApp published this final advisory covering CVE-2025-13867; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49861 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0007/

NetApp published this interim advisory covering CVE-2024-49861; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-41996 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0009/

NetApp published this interim advisory covering CVE-2024-41996; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-26581 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0005/

NetApp published this final advisory covering CVE-2024-26581; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4623 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0006/

NetApp published this interim advisory covering CVE-2023-4623; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40735 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0008/

NetApp published this interim advisory covering CVE-2022-40735; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2002-20001 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0010/

NetApp published this interim advisory covering CVE-2002-20001; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-66863 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0014/

NetApp published this interim advisory covering CVE-2025-66863; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36442 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0002/

NetApp published this final advisory covering CVE-2025-36442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36387 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0008/

NetApp published this final advisory covering CVE-2025-36387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36384 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0004/

NetApp published this final advisory covering CVE-2025-36384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36366 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0007/

NetApp published this final advisory covering CVE-2025-36366; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36184 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0005/

NetApp published this final advisory covering CVE-2025-36184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36123 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0010/

NetApp published this final advisory covering CVE-2025-36123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36008 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0003/

NetApp published this final advisory covering CVE-2025-36008; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36001 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0009/

NetApp published this final advisory covering CVE-2025-36001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2668 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0001/

NetApp published this final advisory covering CVE-2025-2668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47118 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0006/

NetApp published this final advisory covering CVE-2024-47118; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260220-0013

Source: https://security.netapp.com/advisory/NTAP-20260220-0013/

NetApp security advisory NTAP-20260220-0013. CVEs: CVE-2026-0990. Multiple NetApp products incorporate libxml2. Libxml2 versions through 2.15.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

CVE-2025-55193 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0002/

NetApp published this interim advisory covering CVE-2025-55193; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39973 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0016/

NetApp published this interim advisory covering CVE-2025-39973; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39971 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0017/

NetApp published this interim advisory covering CVE-2025-39971; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38622 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0020/

NetApp published this interim advisory covering CVE-2025-38622; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

CVE-2025-36427 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0005/

NetApp published this final advisory covering CVE-2025-36427; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36424 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0007/

NetApp published this final advisory covering CVE-2025-36424; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36423 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0008/

NetApp published this final advisory covering CVE-2025-36423; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36365 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0004/

NetApp published this final advisory covering CVE-2025-36365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36098 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0006/

NetApp published this final advisory covering CVE-2025-36098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36070 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0009/

NetApp published this final advisory covering CVE-2025-36070; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24293 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0001/

NetApp published this interim advisory covering CVE-2025-24293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15079 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0013/

NetApp published this interim advisory covering CVE-2025-15079; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-14819 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0014/

NetApp published this interim advisory covering CVE-2025-14819; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-14524 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0015/

NetApp published this interim advisory covering CVE-2025-14524; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9.

Open source
Advisory

CVE-2025-11002 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0011/

NetApp published this final advisory covering CVE-2025-11002; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-11001 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0012/

NetApp published this final advisory covering CVE-2025-11001; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Trident Autosupport.

Open source
Advisory

CVE-2024-57699 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0003/

NetApp published this final advisory covering CVE-2024-57699; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26594 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0018/

NetApp published this final advisory covering CVE-2024-26594; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24061 GNU Internet Utilities Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0001/

NetApp published this final advisory covering CVE-2026-24061; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8177 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0004/

NetApp published this interim advisory covering CVE-2025-8177; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8176 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0003/

NetApp published this interim advisory covering CVE-2025-8176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5449 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0011/

NetApp published this interim advisory covering CVE-2025-5449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15547 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0015/

NetApp published this final advisory covering CVE-2025-15547; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0736 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0014/

NetApp published this interim advisory covering CVE-2025-0736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2024-8244 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0006/

NetApp published this interim advisory covering CVE-2024-8244; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2023-3603 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0012/

NetApp published this interim advisory covering CVE-2023-3603; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-32253 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0002/

NetApp published this interim advisory covering CVE-2023-32253; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-1667 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0013/

NetApp published this interim advisory covering CVE-2023-1667; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-5397 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0007/

NetApp published this interim advisory covering CVE-2020-5397; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1257 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0008/

NetApp published this interim advisory covering CVE-2018-1257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11040 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0010/

NetApp published this interim advisory covering CVE-2018-11040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11039 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0009/

NetApp published this interim advisory covering CVE-2018-11039; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-69421 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0007/

NetApp published this interim advisory covering CVE-2025-69421; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-69420 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0006/

NetApp published this interim advisory covering CVE-2025-69420; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-69419 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0008/

NetApp published this interim advisory covering CVE-2025-69419; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-69418 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0009/

NetApp published this interim advisory covering CVE-2025-69418; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x.

Open source
Advisory

CVE-2025-68813 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0002/

NetApp published this interim advisory covering CVE-2025-68813; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68160 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0010/

NetApp published this interim advisory covering CVE-2025-68160; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x.

Open source
Advisory

CVE-2025-66199 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0015/

NetApp published this interim advisory covering CVE-2025-66199; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-15469 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0014/

NetApp published this interim advisory covering CVE-2025-15469; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-15468 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0013/

NetApp published this interim advisory covering CVE-2025-15468; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-15467 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0011/

NetApp published this interim advisory covering CVE-2025-15467; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp Console Agent Container (storage_services); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-11187 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0012/

NetApp published this interim advisory covering CVE-2025-11187; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP 9.

Open source
Advisory

CVE-2024-56779 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0001/

NetApp published this interim advisory covering CVE-2024-56779; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

2026-09-01-ntap-20260204-0005

Source: https://security.netapp.com/advisory/NTAP-20260204-0005/

NetApp security advisory NTAP-20260204-0005. CVEs: CVE-2026-22795. Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1. are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260204-0004

Source: https://security.netapp.com/advisory/NTAP-20260204-0004/

NetApp security advisory NTAP-20260204-0004. CVEs: CVE-2026-22796. Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

September 2025 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0016/

NetApp published this interim advisory covering CVE-2025-58056, CVE-2025-58057; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2026-0672 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0007/

NetApp published this interim advisory covering CVE-2026-0672; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-68973 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0014/

NetApp published this interim advisory covering CVE-2025-68973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68493 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0012/

NetApp published this final advisory covering CVE-2025-68493; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68390 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0018/

NetApp published this interim advisory covering CVE-2025-68390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68384 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0019/

NetApp published this interim advisory covering CVE-2025-68384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-67735 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0017/

NetApp published this final advisory covering CVE-2025-67735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61729 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0002/

NetApp published this interim advisory covering CVE-2025-61729; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident.

Open source
Advisory

CVE-2025-61727 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0003/

NetApp published this interim advisory covering CVE-2025-61727; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident; Trident Protect.

Open source
Advisory

CVE-2025-5916 Libarchive Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0020/

NetApp published this interim advisory covering CVE-2025-5916; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24528 Kerberos Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0015/

NetApp published this final advisory covering CVE-2025-24528; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-14017 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0009/

NetApp published this interim advisory covering CVE-2025-14017; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-13878 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0001/

NetApp published this interim advisory covering CVE-2025-13878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-12543 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0005/

NetApp published this interim advisory covering CVE-2025-12543; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-3884 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0004/

NetApp published this interim advisory covering CVE-2024-3884; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-23944 Apache ZooKeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0008/

NetApp published this interim advisory covering CVE-2024-23944; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

2026-09-01-ntap-20260130-0011

Source: https://security.netapp.com/advisory/NTAP-20260130-0011/

NetApp security advisory NTAP-20260130-0011. CVEs: CVE-2026-22801. Multiple NetApp products incorporate libpng. Libpng versions 1.6.26 prior to 1.6.54 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS).

Open source
Advisory

2026-09-01-ntap-20260130-0010

Source: https://security.netapp.com/advisory/NTAP-20260130-0010/

NetApp security advisory NTAP-20260130-0010. CVEs: CVE-2026-21441. Multiple NetApp products incorporate Urllib3. Urllib3 versions 1.22 prior to 2.6.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

January 2026 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0009/

NetApp published this interim advisory covering CVE-2025-9230, CVE-2026-21964, CVE-2026-21968, CVE-2026-21948, CVE-2026-21936, CVE-2026-21941, CVE-2026-21937; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

January 2026 MySQL Server 9.0.0 through 9.5.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0010/

NetApp published this interim advisory covering CVE-2026-21950, CVE-2026-21965, CVE-2026-21952, CVE-2026-21949, CVE-2026-21929; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2026 Java Platform Standard Edition 8u471-b50 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0013/

NetApp published this interim advisory covering CVE-2025-47219, CVE-2026-21947, CVE-2025-6052, CVE-2025-7425, CVE-2025-43368, CVE-2025-6021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6965 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0011/

NetApp published this interim advisory covering CVE-2025-6965; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-68161 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0014/

NetApp published this interim advisory covering CVE-2025-68161; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent; NetApp Manageability SDK.

Open source
Advisory

CVE-2025-66568 Ruby-Saml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0002/

NetApp published this final advisory covering CVE-2025-66568; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-66567 Ruby-Saml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0003/

NetApp published this final advisory covering CVE-2025-66567; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-62507 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0015/

NetApp published this final advisory covering CVE-2025-62507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40027 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0005/

NetApp published this interim advisory covering CVE-2025-40027; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38732 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0006/

NetApp published this interim advisory covering CVE-2025-38732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-30065 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0008/

NetApp published this final advisory covering CVE-2025-30065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2025 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0007/

NetApp published this final advisory covering CVE-2017-15422, CVE-2017-7868, CVE-2011-4599, CVE-2014-7923, CVE-2017-7867, CVE-2016-6293, CVE-2017-15396, CVE-2020-21913, CVE-2020-10531, CVE-2016-7415, CVE-2017-17484, CVE-2017-14952; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

2026-09-01-ntap-20260123-0012

Source: https://security.netapp.com/advisory/NTAP-20260123-0012/

NetApp security advisory NTAP-20260123-0012. CVEs: CVE-2026-21932, CVE-2026-21945, CVE-2026-21925, CVE-2026-21933. Multiple NetApp products incorporate the Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1 are susceptible to vulnerabilities that could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details.

Open source
Advisory

Intel SA-01367 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0015/

NetApp published this interim advisory covering CVE-2025-26403, CVE-2025-32086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39946 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0010/

NetApp published this interim advisory covering CVE-2025-39946; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39943 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0011/

NetApp published this final advisory covering CVE-2025-39943; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38728 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0008/

NetApp published this final advisory covering CVE-2025-38728; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38491 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0006/

NetApp published this interim advisory covering CVE-2025-38491; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-38465 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0005/

NetApp published this interim advisory covering CVE-2025-38465; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2025-38430 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0004/

NetApp published this interim advisory covering CVE-2025-38430; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-38181 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0009/

NetApp published this interim advisory covering CVE-2025-38181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22889 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0014/

NetApp published this interim advisory covering CVE-2025-22889; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22840 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0013/

NetApp published this interim advisory covering CVE-2025-22840; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22839 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0012/

NetApp published this interim advisory covering CVE-2025-22839; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36927 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0001/

NetApp published this interim advisory covering CVE-2024-36927; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36903 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0002/

NetApp published this interim advisory covering CVE-2024-36903; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-7425 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0014/

NetApp published this interim advisory covering CVE-2025-7425; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-66293 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0006/

NetApp published this interim advisory covering CVE-2025-66293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-65018 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0003/

NetApp published this interim advisory covering CVE-2025-65018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-64720 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0004/

NetApp published this interim advisory covering CVE-2025-64720; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-64505 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0007/

NetApp published this interim advisory covering CVE-2025-64505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61919 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0011/

NetApp published this final advisory covering CVE-2025-61919; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61780 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0009/

NetApp published this final advisory covering CVE-2025-61780; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61772 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0010/

NetApp published this final advisory covering CVE-2025-61772; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61771 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0012/

NetApp published this final advisory covering CVE-2025-61771; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61770 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0008/

NetApp published this final advisory covering CVE-2025-61770; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-58767 Ruby/Rexml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0020/

NetApp published this interim advisory covering CVE-2025-58767; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5222 ICU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0002/

NetApp published this interim advisory covering CVE-2025-5222; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-27558 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0017/

NetApp published this interim advisory covering CVE-2025-27558; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-36913 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0018/

NetApp published this interim advisory covering CVE-2024-36913; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-36357 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0016/

NetApp published this interim advisory covering CVE-2024-36357; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-36350 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0015/

NetApp published this interim advisory covering CVE-2024-36350; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-25062 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0019/

NetApp published this interim advisory covering CVE-2024-25062; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP 9.

Open source
Advisory

CVE-2023-40403 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260116-0013/

NetApp published this interim advisory covering CVE-2023-40403, CVE-2022-4909; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

2026-09-01-ntap-20260116-0005

Source: https://security.netapp.com/advisory/NTAP-20260116-0005/

NetApp security advisory NTAP-20260116-0005. CVEs: CVE-2025-64506. Multiple NetApp products incorporate libpng. Libpng versions 1.6.0 prior to 1.6.51 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS).

Open source
Advisory

CVE-2025-9900 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0012/

NetApp published this final advisory covering CVE-2025-9900; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-9566 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0007/

NetApp published this final advisory covering CVE-2025-9566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8961 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0014/

NetApp published this interim advisory covering CVE-2025-8961; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8534 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0015/

NetApp published this interim advisory covering CVE-2025-8534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8114 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0010/

NetApp published this interim advisory covering CVE-2025-8114; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68615 Net-SNMP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0002/

NetApp published this interim advisory covering CVE-2025-68615; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5987 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0009/

NetApp published this interim advisory covering CVE-2025-5987; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-59419 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0001/

NetApp published this interim advisory covering CVE-2025-59419; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2025-54350 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0006/

NetApp published this final advisory covering CVE-2025-54350; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4878 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0008/

NetApp published this interim advisory covering CVE-2025-4878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4877 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0011/

NetApp published this interim advisory covering CVE-2025-4877; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20109 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0003/

NetApp published this interim advisory covering CVE-2025-20109; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52355 Libtiff Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0013/

NetApp published this final advisory covering CVE-2023-52355; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-41419 Gevent Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260109-0005/

NetApp published this final advisory covering CVE-2023-41419; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7424 Libxslt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0012/

NetApp published this interim advisory covering CVE-2025-7424; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6965 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0013/

NetApp published this interim advisory covering CVE-2025-6965; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-53816 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0015/

NetApp published this final advisory covering CVE-2025-53816; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-5318 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0001/

NetApp published this interim advisory covering CVE-2025-5318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5278 GNU Coreutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0011/

NetApp published this interim advisory covering CVE-2025-5278; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-50181 Urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0005/

NetApp published this interim advisory covering CVE-2025-50181; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp Data Classification.

Open source
Advisory

CVE-2025-38092 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0008/

NetApp published this final advisory covering CVE-2025-38092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38089 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0009/

NetApp published this interim advisory covering CVE-2025-38089; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14847 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0016/

NetApp published this interim advisory covering CVE-2025-14847; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-1220 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0014/

NetApp published this final advisory covering CVE-2025-1220; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1125 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0002/

NetApp published this interim advisory covering CVE-2025-1125; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-0689 Grub Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0003/

NetApp published this interim advisory covering CVE-2025-0689; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-45217 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0007/

NetApp published this final advisory covering CVE-2024-45217; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27281 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260102-0006/

NetApp published this interim advisory covering CVE-2024-27281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source