Based on the NetApp Knowledge Base and NetApp’s CVE-2026-15308 advisory record. Only claims present in the verified advisory and KB sources are asserted here.
Security AIQUM CVE-2026-15308 2026-10-07What the advisory says
CVE-2026-15308 carries a CVSS 4.0 base score of 8.7 (High) in NetApp’s advisory record. The scoring vector — AV:N/AC:L/AT:N/PR:N/UI:N/VA:H — describes a network-reachable flaw that needs no privileges and no user interaction, and whose only scored impact is availability: successful exploitation can cause a denial of service. NetApp lists exploitation as public, so proof-of-concept detail is already in circulation. For a management-plane service that is reachable from the network, that combination is enough to put the fix on the calendar.
Who is affected
NetApp’s affected-product list for CVE-2026-15308 sits in the identity and management tier rather than on the storage controllers: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, and Management Services for Element Software and NetApp HCI. If you run AIQUM, inventory that deployment first — the Windows build is the one the new KB guidance targets. ONTAP itself is not on the CVE-2026-15308 affected list; this is a management-plane remediation.
The remediation is a manual Python upgrade
The advisory record for CVE-2026-15308 lists no packaged fix, and the path NetApp documents is a manual Python upgrade. NetApp Knowledge Base published step-by-step guidance titled “How to manually upgrade Python to address CVE-2026-15308 and CVE-2026-11972 in AIQUM 9.18 Windows.” The same article covers a second vulnerability, CVE-2026-11972, on the same Windows platform. Because the fix is applied by hand rather than through a routine package update, your normal patch tooling will not pick it up on its own — it has to be scheduled and tracked deliberately.
First checks for admins
Before scheduling anything, confirm what you actually run and how it is exposed:
- Read the AIQUM version and platform from the About panel or the CLI and confirm whether you are on the Windows deployment the KB article addresses.
- Check whether the AIQUM management interface is reachable from more than a hardened jump host. A public-exploit DoS is only urgent if the service is exposed; an allowlisted endpoint has a smaller window.
- Plan the Python upgrade against the AIQUM maintenance you already do, and keep it separate from any ONTAP upgrade in flight. Our notes on the ONTAP upgrade process and ONTAP upgrade paths cover the storage-side sequencing, which is a different track.
- Re-audit who can reach the management tier and tighten it — see our security section for advisory context.
What to watch next
Expect NetApp to fold this into a packaged AIQUM update — manual Python upgrades are usually a stopgap — and watch for the CVE-2026-11972 specifics to be documented alongside it. Until then, treat CVE-2026-15308 as a scheduled maintenance item, not a same-day emergency, unless your AIQUM endpoint is internet-exposed. We track the advisory and will update this page if NetApp changes the remediation status.
Sources: NetApp Knowledge Base — “How to manually upgrade Python to address CVE-2026-15308 and CVE-2026-11972 in AIQUM 9.18 Windows” (5 Oct 2026); NetApp advisory record for CVE-2026-15308 (CVSS 4.0 8.7 High; public exploitation).