Content Library · Advisory

Advisory 2026

Browse 895 2026 NetApp advisory records in the NetApp Black Box content library. Page 7 of 8.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2026-24733 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0002/

NetApp published this interim advisory covering CVE-2026-24733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8191 Swagger UI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0011/

NetApp published this interim advisory covering CVE-2025-8191; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent).

Open source
Advisory

CVE-2025-66614 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0001/

NetApp published this interim advisory covering CVE-2025-66614; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-66516 Apache Tika Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0004/

NetApp published this interim advisory covering CVE-2025-66516; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36425 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0015/

NetApp published this final advisory covering CVE-2025-36425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36247 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0012/

NetApp published this final advisory covering CVE-2025-36247; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-14689 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0014/

NetApp published this final advisory covering CVE-2025-14689; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-13867 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0013/

NetApp published this final advisory covering CVE-2025-13867; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49861 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0007/

NetApp published this interim advisory covering CVE-2024-49861; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2024-41996 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0009/

NetApp published this interim advisory covering CVE-2024-41996; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-26581 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0005/

NetApp published this final advisory covering CVE-2024-26581; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4623 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0006/

NetApp published this interim advisory covering CVE-2023-4623; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-40735 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0008/

NetApp published this interim advisory covering CVE-2022-40735; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2002-20001 Diffie-Hellman Key Exchange Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260227-0010/

NetApp published this interim advisory covering CVE-2002-20001; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Manageability SDK; NetApp Shift Toolkit; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-66863 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0014/

NetApp published this interim advisory covering CVE-2025-66863; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36442 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0002/

NetApp published this final advisory covering CVE-2025-36442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36387 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0008/

NetApp published this final advisory covering CVE-2025-36387; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36384 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0004/

NetApp published this final advisory covering CVE-2025-36384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36366 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0007/

NetApp published this final advisory covering CVE-2025-36366; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36184 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0005/

NetApp published this final advisory covering CVE-2025-36184; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36123 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0010/

NetApp published this final advisory covering CVE-2025-36123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36008 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0003/

NetApp published this final advisory covering CVE-2025-36008; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36001 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0009/

NetApp published this final advisory covering CVE-2025-36001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-2668 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0001/

NetApp published this final advisory covering CVE-2025-2668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47118 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260220-0006/

NetApp published this final advisory covering CVE-2024-47118; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55193 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0002/

NetApp published this interim advisory covering CVE-2025-55193; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39973 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0016/

NetApp published this interim advisory covering CVE-2025-39973; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39971 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0017/

NetApp published this interim advisory covering CVE-2025-39971; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38622 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0020/

NetApp published this interim advisory covering CVE-2025-38622; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

CVE-2025-36427 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0005/

NetApp published this final advisory covering CVE-2025-36427; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36424 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0007/

NetApp published this final advisory covering CVE-2025-36424; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36423 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0008/

NetApp published this final advisory covering CVE-2025-36423; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36365 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0004/

NetApp published this final advisory covering CVE-2025-36365; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36098 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0006/

NetApp published this final advisory covering CVE-2025-36098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36070 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0009/

NetApp published this final advisory covering CVE-2025-36070; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24293 Ruby Gem Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0001/

NetApp published this interim advisory covering CVE-2025-24293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15079 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0013/

NetApp published this interim advisory covering CVE-2025-15079; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-14819 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0014/

NetApp published this interim advisory covering CVE-2025-14819; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-14524 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0015/

NetApp published this interim advisory covering CVE-2025-14524; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9.

Open source
Advisory

CVE-2025-11002 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0011/

NetApp published this final advisory covering CVE-2025-11002; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-11001 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0012/

NetApp published this final advisory covering CVE-2025-11001; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Trident Autosupport.

Open source
Advisory

CVE-2024-57699 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0003/

NetApp published this final advisory covering CVE-2024-57699; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26594 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260213-0018/

NetApp published this final advisory covering CVE-2024-26594; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2026-24061 GNU Internet Utilities Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0001/

NetApp published this final advisory covering CVE-2026-24061; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8177 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0004/

NetApp published this interim advisory covering CVE-2025-8177; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-8176 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0003/

NetApp published this interim advisory covering CVE-2025-8176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5449 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0011/

NetApp published this interim advisory covering CVE-2025-5449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-15547 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0015/

NetApp published this final advisory covering CVE-2025-15547; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0736 Infinispan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0014/

NetApp published this interim advisory covering CVE-2025-0736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2024-8244 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0006/

NetApp published this interim advisory covering CVE-2024-8244; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2023-3603 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0012/

NetApp published this interim advisory covering CVE-2023-3603; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-32253 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0002/

NetApp published this interim advisory covering CVE-2023-32253; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-1667 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0013/

NetApp published this interim advisory covering CVE-2023-1667; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-5397 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0007/

NetApp published this interim advisory covering CVE-2020-5397; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1257 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0008/

NetApp published this interim advisory covering CVE-2018-1257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11040 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0010/

NetApp published this interim advisory covering CVE-2018-11040; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-11039 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260206-0009/

NetApp published this interim advisory covering CVE-2018-11039; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-69421 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0007/

NetApp published this interim advisory covering CVE-2025-69421; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-69420 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0006/

NetApp published this interim advisory covering CVE-2025-69420; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-69419 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0008/

NetApp published this interim advisory covering CVE-2025-69419; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-69418 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0009/

NetApp published this interim advisory covering CVE-2025-69418; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x.

Open source
Advisory

CVE-2025-68813 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0002/

NetApp published this interim advisory covering CVE-2025-68813; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68160 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0010/

NetApp published this interim advisory covering CVE-2025-68160; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x.

Open source
Advisory

CVE-2025-66199 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0015/

NetApp published this interim advisory covering CVE-2025-66199; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-15469 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0014/

NetApp published this interim advisory covering CVE-2025-15469; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-15468 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0013/

NetApp published this interim advisory covering CVE-2025-15468; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-15467 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0011/

NetApp published this interim advisory covering CVE-2025-15467; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp Console Agent Container (cbs-backend); NetApp Console Agent Container (storage_services); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-11187 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0012/

NetApp published this interim advisory covering CVE-2025-11187; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp LOADER 8.x; ONTAP 9.

Open source
Advisory

CVE-2024-56779 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260204-0001/

NetApp published this interim advisory covering CVE-2024-56779; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

September 2025 Apache Netty Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0016/

NetApp published this interim advisory covering CVE-2025-58056, CVE-2025-58057; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2026-0672 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0007/

NetApp published this interim advisory covering CVE-2026-0672; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2025-68973 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0014/

NetApp published this interim advisory covering CVE-2025-68973; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68493 Apache Struts Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0012/

NetApp published this final advisory covering CVE-2025-68493; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68390 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0018/

NetApp published this interim advisory covering CVE-2025-68390; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-68384 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0019/

NetApp published this interim advisory covering CVE-2025-68384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-67735 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0017/

NetApp published this final advisory covering CVE-2025-67735; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-61729 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0002/

NetApp published this interim advisory covering CVE-2025-61729; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident.

Open source
Advisory

CVE-2025-61727 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0003/

NetApp published this interim advisory covering CVE-2025-61727; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent; NetApp Console Agent; ONTAP tools for VMware vSphere 10; Trident; Trident Protect.

Open source
Advisory

CVE-2025-5916 Libarchive Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0020/

NetApp published this interim advisory covering CVE-2025-5916; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24528 Kerberos Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0015/

NetApp published this final advisory covering CVE-2025-24528; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-14017 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0009/

NetApp published this interim advisory covering CVE-2025-14017; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-13878 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0001/

NetApp published this interim advisory covering CVE-2025-13878; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-12543 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0005/

NetApp published this interim advisory covering CVE-2025-12543; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-3884 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0004/

NetApp published this interim advisory covering CVE-2024-3884; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-23944 Apache ZooKeeper Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260130-0008/

NetApp published this interim advisory covering CVE-2024-23944; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent.

Open source
Advisory

January 2026 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0009/

NetApp published this interim advisory covering CVE-2025-9230, CVE-2026-21964, CVE-2026-21968, CVE-2026-21948, CVE-2026-21936, CVE-2026-21941, CVE-2026-21937; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; SnapCenter.

Open source
Advisory

January 2026 MySQL Server 9.0.0 through 9.5.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0010/

NetApp published this interim advisory covering CVE-2026-21950, CVE-2026-21965, CVE-2026-21952, CVE-2026-21949, CVE-2026-21929; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2026 Java Platform Standard Edition 8u471-b50 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0013/

NetApp published this interim advisory covering CVE-2025-47219, CVE-2026-21947, CVE-2025-6052, CVE-2025-7425, CVE-2025-43368, CVE-2025-6021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6965 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0011/

NetApp published this interim advisory covering CVE-2025-6965; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-68161 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0014/

NetApp published this interim advisory covering CVE-2025-68161; the API labels exploitation information as **Public**. The API currently lists affected products as: Data Infrastructure Insights and Data Secure Storage Workload Security Agent; NetApp Manageability SDK.

Open source
Advisory

CVE-2025-66568 Ruby-Saml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0002/

NetApp published this final advisory covering CVE-2025-66568; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-66567 Ruby-Saml Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0003/

NetApp published this final advisory covering CVE-2025-66567; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-62507 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0015/

NetApp published this final advisory covering CVE-2025-62507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40027 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0005/

NetApp published this interim advisory covering CVE-2025-40027; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-38732 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0006/

NetApp published this interim advisory covering CVE-2025-38732; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-30065 IBM DB2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0008/

NetApp published this final advisory covering CVE-2025-30065; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2025 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260123-0007/

NetApp published this final advisory covering CVE-2017-15422, CVE-2017-7868, CVE-2011-4599, CVE-2014-7923, CVE-2017-7867, CVE-2016-6293, CVE-2017-15396, CVE-2020-21913, CVE-2020-10531, CVE-2016-7415, CVE-2017-17484, CVE-2017-14952; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

Intel SA-01367 Processor Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0015/

NetApp published this interim advisory covering CVE-2025-26403, CVE-2025-32086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-39946 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0010/

NetApp published this interim advisory covering CVE-2025-39946; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-39943 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0011/

NetApp published this final advisory covering CVE-2025-39943; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38728 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0008/

NetApp published this final advisory covering CVE-2025-38728; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-38491 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0006/

NetApp published this interim advisory covering CVE-2025-38491; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-38465 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0005/

NetApp published this interim advisory covering CVE-2025-38465; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2025-38430 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0004/

NetApp published this interim advisory covering CVE-2025-38430; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2025-38181 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0009/

NetApp published this interim advisory covering CVE-2025-38181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22889 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20260121-0014/

NetApp published this interim advisory covering CVE-2025-22889; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source