Content Library · Advisory

Advisory 2026

Browse 895 2026 NetApp advisory records in the NetApp Black Box content library. Page 2 of 8.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0017/

NetApp published this interim advisory covering CVE-2026-17106; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0017

NetApp published security advisory NTAP-20260828-0017 on 2026-08-28, CVE-2026-17106. Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

CVE-2026-15571 Keycloak Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260828-0007/

NetApp published this interim advisory covering CVE-2026-15571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-15571 Keycloak Vulnerability in NetApp Products

Source: NetApp Security Advisory NTAP-20260828-0007

NetApp published security advisory NTAP-20260828-0007 on 2026-08-28, CVE-2026-15571. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-15308 CPython Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0016 (2026-08-28) (interim — details may evolve) covering CVE-2026-15308. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-12617 ISC BIND Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260730-0005 (2026-08-28) (interim — details may evolve) covering CVE-2026-12617. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-0990 Libxml2 Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260220-0013 (2026-08-28) (interim — details may evolve) covering CVE-2026-0990. The advisory affects NetApp Manageability SDK, ONTAP 9. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

April 2026 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260429-0012 (2026-08-28) (interim — details may evolve) covering CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: 1 fix entries. Impact: Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized access to critical data or complete access to all Oracle Java SE accessible data or the unauthorized ability to cause a partial Denial of Se Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

2026-09-02-2026-08-28-june-2026-freebsd-zfs-vulnerabilities-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0005

June 2026 FreeBSD ZFS Vulnerabilities in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-49429, CVE-2026-49430, CVE-2026-49431. All supported versions of FreeBSD are susceptible to vulnerabilities in ZFS which when successfully exploited could allow local users with various permissions to trigger a kernel heap overflow, trigger kernel memory corruption or set the internal ZFS metadata flag "$hasrecvd" on datasets.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59889-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0016

CVE-2026-59889 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59889. FasterXML Jackson Databind versions 2.18.0-rc1 through 2.18.8, 2.18.0-rc1 through 2.18.8, 2.21.0 through 2.21.4, 2.21.0 through 2.21.4, 2.22.0 through 2.22.0, 2.22.0 through 2.22.0, 3.0.0-rc1 through 3.1.4, 3.0.0-rc1 through 3.1.4, 3.2.0 through 3.2.0, and 3.2.0 through 3.2.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59888-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0015

CVE-2026-59888 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59888. FasterXML Jackson Databind versions 2.15.0-rc1 through 2.18.7, 2.19.0-rc2 through 2.21.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59875-tar-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0004

CVE-2026-59875 Tar Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-59875. Tar versions prior to 7.5.17 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59871-tar-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0003

CVE-2026-59871 Tar Vulnerability in NetApp Products. Affected: NetApp HCI Baseboard Management Controller (BMC) - H610S. CVEs: CVE-2026-59871. Tar versions prior to 7.5.18 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-59250-erlang-otp-vulnerability-in-netapp

Source: https://security.netapp.com/advisory/NTAP-20260828-0009

CVE-2026-59250 Erlang/OTP Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-59250. Erlang/OTP versions 17.0 prior to 29.0.4 and 28.5.0.4 prior to 27.3.4.15 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-55953-erlang-otp-vulnerability-in-netapp

Source: https://security.netapp.com/advisory/NTAP-20260828-0008

CVE-2026-55953 Erlang/OTP Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-55953. Erlang/OTP versions R13B03 prior to 27.3.4.15, from 28.0 prior to 28.5.0.4, and from 29.0 prior to 29.0.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54513-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0014

CVE-2026-54513 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54513. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54512-fasterxml-jackson-databind-vulnera

Source: https://security.netapp.com/advisory/NTAP-20260828-0013

CVE-2026-54512 FasterXML Jackson Databind Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54512. FasterXML Jackson Databind versions 2.10.0-pr1 through 2.18.7, 2.10.0-pr1 through 2.18.7, 2.19.0-rc2 through 2.21.3, 2.19.0-rc2 through 2.21.3, 3.0.0-rc1 through 3.1.3, and 3.0.0-rc1 through 3.1.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54370-acl-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0011

CVE-2026-54370 Acl Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54370. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-54369-acl-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0010

CVE-2026-54369 Acl Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54369. Acl versions prior to 2.4.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-45292-opentelemetry-java-vulnerability-i

Source: https://security.netapp.com/advisory/NTAP-20260828-0020

CVE-2026-45292 OpenTelemetry Java Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-45292. OpenTelemetry Java versions through 1.61.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44604-rpm-vulnerability-in-netapp-produc

Source: https://security.netapp.com/advisory/NTAP-20260828-0018

CVE-2026-44604 RPM Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-44604. RPM versions through 6.1.0-RC1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44604-attr-vulnerability-in-netapp-produ

Source: https://security.netapp.com/advisory/NTAP-20260828-0012

CVE-2026-44604 Attr Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-54371. Attr versions prior to 2.6.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-44170-mariadb-vulnerability-in-netapp-pr

Source: https://security.netapp.com/advisory/NTAP-20260828-0019

CVE-2026-44170 Mariadb Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-44170. MariaDB versions 10.6.1 prior to 10.6.25, 10.11.1 prior to 10.11.17, 11.4.1 prior to 11.4.11, 11.8.1 prior to 11.8.7, and 12.3.1 prior to 12.3.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-22056-denial-of-service-vulnerability-in

Source: https://security.netapp.com/advisory/NTAP-20260828-0021

CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale). Affected: StorageGRID (formerly StorageGRID Webscale). CVEs: CVE-2026-22056. StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could allow an attacker with some control over the environment to cause a partial Denial of Service.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-18963-keycloak-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0006

CVE-2026-18963 Keycloak Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-18963. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-17106-docker-engine-vulnerability-in-net

Source: https://security.netapp.com/advisory/NTAP-20260828-0017

CVE-2026-17106 Docker Engine Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-17106. Docker Engine versions prior to 29.7.2 are susceptible to a vulnerability via moby/go-archive which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

2026-09-02-2026-08-28-cve-2026-15571-keycloak-vulnerability-in-netapp-p

Source: https://security.netapp.com/advisory/NTAP-20260828-0007

CVE-2026-15571 Keycloak Vulnerability in NetApp Products. Affected: multiple NetApp products. CVEs: CVE-2026-15571. Keycloak versions prior to 26.7.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

CVE-2026-3644 Python Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0020 (2026-08-26) (interim — details may evolve) covering CVE-2026-3644. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-34282 Java Platform Standard Edition Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260429-0011 (2026-08-26) (interim — details may evolve) covering CVE-2026-34282. The advisory affects Data Infrastructure Insights and Data Secure Storage Workload Security Agent, NetApp Console Agent, OnCommand Insight. Fix status: 1 fix entries. Impact: Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33939 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0008 (2026-08-26) (interim — details may evolve) covering CVE-2026-33939. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-32597 PyJWT Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0010 (2026-08-26) (interim — details may evolve) covering CVE-2026-32597. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-60005 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260730-0010 (2026-08-25) (interim — details may evolve) covering CVE-2026-60005. The advisory affects NetApp Console Agent Container (static-file-server). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-42533 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0001 (2026-08-25) (interim — details may evolve) covering CVE-2026-42533. The advisory affects NetApp Console Agent Container (static-file-server). Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4046 GNU C Library (glibc) Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260422-0003 (2026-08-25) (interim — details may evolve) covering CVE-2026-4046. The advisory affects Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-27448 pyOpenSSL Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0013 (2026-08-25) (interim — details may evolve) covering CVE-2026-27448. The advisory affects NetApp Data Classification. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-42945 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260522-0011 (2026-08-24) (interim — details may evolve) covering CVE-2026-42945. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22801 Libpng Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260130-0011 (2026-08-24) (interim — details may evolve) covering CVE-2026-22801. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

May 2026 GnuTLS Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0002 (2026-08-21) (interim — details may evolve) covering CVE-2026-33845, CVE-2026-33846, CVE-2026-3833. The advisory affects Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP Select Deploy administration utility. Fix status: 1 fix entries. Impact: Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

May 2026 Apache ActiveMQ Vulnerabilities in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260710-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-42253, CVE-2026-42588, CVE-2026-45505, CVE-2026-46605, CVE-2026-49157, CVE-2026-49270. The advisory affects E-Series SANtricity Unified Manager and Web Services Proxy, SANtricity Storage Plugin for vCenter. Fix status: Fix status not yet published. Impact: Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-9256 NGINX Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260605-0012 (2026-08-21) (interim — details may evolve) covering CVE-2026-9256. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-70906 Java SE Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0008/

NetApp published this interim advisory covering CVE-2026-70906; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6949 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0020/

NetApp published this interim advisory covering CVE-2026-6949; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-6100 CPython Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260717-0015 (2026-08-21) (interim — details may evolve) covering CVE-2026-6100. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-58224 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0019/

NetApp published this final advisory covering CVE-2026-58224; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58222 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0018/

NetApp published this interim advisory covering CVE-2026-58222; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58221 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0017/

NetApp published this interim advisory covering CVE-2026-58221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58218 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0016/

NetApp published this interim advisory covering CVE-2026-58218; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58216 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0015/

NetApp published this interim advisory covering CVE-2026-58216; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58043 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0001/

NetApp published this interim advisory covering CVE-2026-58043; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-46300 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260522-0016 (2026-08-21) (interim — details may evolve) covering CVE-2026-46300. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4519 Python Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0019 (2026-08-21) (interim — details may evolve) covering CVE-2026-4519. The advisory affects Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-4408 Samba Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260527-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-4408. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-40976 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0005/

NetApp published this interim advisory covering CVE-2026-40976; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-34197 Apache ActiveMQ Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0001 (2026-08-21) covering CVE-2026-34197. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33941 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0006 (2026-08-21) (interim — details may evolve) covering CVE-2026-33941. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33940 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0007 (2026-08-21) (interim — details may evolve) covering CVE-2026-33940. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-33938 Handlebars.js Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260410-0009 (2026-08-21) (interim — details may evolve) covering CVE-2026-33938. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-29036 cJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0004/

NetApp published this interim advisory covering CVE-2026-29036; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-26007 pyca/cryptography Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260311-0010 (2026-08-21) (interim — details may evolve) covering CVE-2026-26007. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-24842 Node-tar Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260422-0018 (2026-08-21) (interim — details may evolve) covering CVE-2026-24842. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23950 Node-Tar Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260417-0003 (2026-08-21) (interim — details may evolve) covering CVE-2026-23950. The advisory affects NetApp HCI Baseboard Management Controller (BMC) - H610S. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-23231 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0013 (2026-08-21) (interim — details may evolve) covering CVE-2026-23231. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-2303 MongoDB Drivers Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260626-0017 (2026-08-21) (interim — details may evolve) covering CVE-2026-2303. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data. Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22988 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260305-0017 (2026-08-21) (interim — details may evolve) covering CVE-2026-22988. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22984 Linux Kernel Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260508-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-22984. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-22695 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0006/

NetApp published this interim advisory covering CVE-2026-22695; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-22610 Angular Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260311-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-22610. The advisory affects Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1485 GLib Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0001 (2026-08-21) (interim — details may evolve) covering CVE-2026-1485. The advisory affects See advisory. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1484 GLib Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0003 (2026-08-21) (interim — details may evolve) covering CVE-2026-1484. The advisory affects Active IQ Unified Manager for VMware vSphere. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to addition or modification of data or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-14456 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0003/

NetApp published this interim advisory covering CVE-2026-14456; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-14266 7-Zip Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260724-0010 (2026-08-21) (interim — details may evolve) covering CVE-2026-14266. The advisory affects Active IQ Unified Manager for Microsoft Windows. Fix status: Fix status not yet published. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2026-1245 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0002/

NetApp published this interim advisory covering CVE-2026-1245; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-0861 GNU C Library (glibc) Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260320-0005 (2026-08-21) (interim — details may evolve) covering CVE-2026-0861. The advisory affects Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, NetApp HCI Baseboard Management Controller (BMC) - H610S, Trident. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-8885 Bouncy Castle Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20250912-0012 (2026-08-21) (interim — details may evolve) covering CVE-2025-8885. The advisory affects Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, ONTAP tools for VMware vSphere 10. Fix status: 3 fix entries. Impact: Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-64506 Libpng Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20260116-0005 (2026-08-21) (interim — details may evolve) covering CVE-2025-64506. The advisory affects Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. Fix status: 1 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

CVE-2025-52565 Runc Vulnerability in NetApp Products

Source: NetApp Product Security

NetApp published advisory NTAP-20251121-0002 (2026-08-21) (interim — details may evolve) covering CVE-2025-52565. The advisory affects Astra Control Center, ONTAP tools for VMware vSphere 10. Fix status: 2 fix entries. Impact: Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Administrators should compare the affected-version and remediation tables with their inventory.

Open source
Advisory

August 2026 MySQL Connector/ODBC Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260821-0007/

NetApp published this interim advisory covering CVE-2026-71084, CVE-2026-71079, CVE-2026-71073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260821-0014

Source: https://security.netapp.com/advisory/NTAP-20260821-0014/

NetApp security advisory NTAP-20260821-0014. CVEs: CVE-2026-6727. The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which exposes a timing side-channel in RSA OAEP decryption, enabling an attacker to decrypt sensitive blobs (import blobs, credential blobs, and session salts) encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), or to falsify TPM 2.0 Attestation Keys.

Open source
Advisory

2026-09-01-ntap-20260821-0013

Source: https://security.netapp.com/advisory/NTAP-20260821-0013/

NetApp security advisory NTAP-20260821-0013. CVEs: CVE-2026-6726. The TPM 2.0 reference library specification published by the Trusted Computing Group is susceptible to a vulnerability which when exploited could allow improper reuse of object slots between key/data objects and hash contexts, enabling an attacker to falsify TPM attestations and credentials.

Open source
Advisory

2026-09-01-ntap-20260821-0012

Source: https://security.netapp.com/advisory/NTAP-20260821-0012/

NetApp security advisory NTAP-20260821-0012. CVEs: CVE-2026-73283. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0011

Source: https://security.netapp.com/advisory/NTAP-20260821-0011/

NetApp security advisory NTAP-20260821-0011. CVEs: CVE-2026-73282. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0010

Source: https://security.netapp.com/advisory/NTAP-20260821-0010/

NetApp security advisory NTAP-20260821-0010. CVEs: CVE-2026-73281. OpenSSH versions through 10.4 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data.

Open source
Advisory

2026-09-01-ntap-20260821-0009

Source: https://security.netapp.com/advisory/NTAP-20260821-0009/

NetApp security advisory NTAP-20260821-0009. CVEs: CVE-2026-61308, CVE-2026-70907, CVE-2026-60589. Java SE versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2 are susceptible to vulnerabilities that allow unauthenticated attackers with network access via multiple protocols (including HTTP and TLS) to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details.

Open source
Advisory

Intel SA-01234 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0006/

NetApp published this interim advisory covering CVE-2025-20105, CVE-2025-20064, CVE-2025-20028, CVE-2025-20068, CVE-2025-20027, CVE-2025-22850, CVE-2025-22444, CVE-2025-20005, CVE-2025-20073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-7598 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0020/

NetApp published this interim advisory covering CVE-2026-7598; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-64535 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0004/

NetApp published this interim advisory covering CVE-2026-64535; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-64391 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0002/

NetApp published this interim advisory covering CVE-2026-64391; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-64319 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0005/

NetApp published this interim advisory covering CVE-2026-64319; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58088 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0015/

NetApp published this final advisory covering CVE-2026-58088; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58087 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0014/

NetApp published this final advisory covering CVE-2026-58087; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58086 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0017/

NetApp published this interim advisory covering CVE-2026-58086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58085 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0016/

NetApp published this interim advisory covering CVE-2026-58085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58084 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0018/

NetApp published this interim advisory covering CVE-2026-58084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-58083 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0013/

NetApp published this final advisory covering CVE-2026-58083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-54876 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0019/

NetApp published this interim advisory covering CVE-2026-54876; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-45205 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0010/

NetApp published this interim advisory covering CVE-2026-45205; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-31589 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0001/

NetApp published this interim advisory covering CVE-2026-31589; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18097 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0009/

NetApp published this final advisory covering CVE-2026-18097; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-18096 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0012/

NetApp published this final advisory covering CVE-2026-18096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-16480 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0011/

NetApp published this final advisory covering CVE-2026-16480; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10543 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0008/

NetApp published this interim advisory covering CVE-2026-10543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-10534 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260814-0007/

NetApp published this final advisory covering CVE-2026-10534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

2026-09-01-ntap-20260814-0003

Source: https://security.netapp.com/advisory/NTAP-20260814-0003/

NetApp security advisory NTAP-20260814-0003. CVEs: CVE-2026-64534. Linux kernel versions prior to 5.10.261, 5.11.0 prior to 5.15.212, 5.16.0 prior to 6.1.178, 6.2.0 prior to 6.6.145, 6.7.0 prior to 6.12.97, 6.13.0 prior to 6.18.40, and 6.19.0 prior to 7.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Open source
Advisory

NetApp Advisories Batch — NTAP-20260807-0001 to -0020

Source: security.netapp.com advisory API

Twenty advisories published Aug 7, 2026: four Libssh2 CVEs (CVE-2026-66032/-33/-34/-35), five Linux Kernel issues including CVE-2026-64531, Tar CVE-2026-53655, ten Libssh CVEs (CVE-2026-15370, -59844/-59845/-59847/-59850/-59846/-59848/-59849, etc.), and five Elasticsearch vulnerabilities (CVE-2026-56145, -63136, -63140, -63144, -63263, -56144). Libssh/Libssh2 flaws are relevant to any NetApp product bundling SSH client libraries — verify fix availability per product.

Open source
Advisory

CVE-2026-66035 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0004/

NetApp published this interim advisory covering CVE-2026-66035; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-66034 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0003/

NetApp published this interim advisory covering CVE-2026-66034; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-66033 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0002/

NetApp published this interim advisory covering CVE-2026-66033; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-66032 Libssh2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0001/

NetApp published this interim advisory covering CVE-2026-66032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2026-64531 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0005/

NetApp published this interim advisory covering CVE-2026-64531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63263 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0019/

NetApp published this interim advisory covering CVE-2026-63263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63144 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0018/

NetApp published this interim advisory covering CVE-2026-63144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63140 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0017/

NetApp published this interim advisory covering CVE-2026-63140; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-63136 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0016/

NetApp published this interim advisory covering CVE-2026-63136; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59850 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0011/

NetApp published this interim advisory covering CVE-2026-59850; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59849 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0014/

NetApp published this interim advisory covering CVE-2026-59849; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59848 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0013/

NetApp published this interim advisory covering CVE-2026-59848; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-59847 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260807-0010/

NetApp published this interim advisory covering CVE-2026-59847; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source