Home / News & Releases / CVE-2026-15308 (CVSS 8.7): NetApp AIQUM guidance to manually

CVE-2026-15308 (CVSS 8.7): NetApp AIQUM guidance to manually upgrade Python on Windows

NetApp KB guidance to manually upgrade Python in Active IQ Unified Manager (AIQUM) 9.18 on Windows to address CVE-2026-15308 and CVE-2026-11972 — a network-reachable denial-of-service flaw with public exploitation.

Security analysis · October 7, 2026. Based on NetApp’s advisory record for CVE-2026-15308 and the NetApp Knowledge Base article on upgrading Python in AIQUM 9.18 for Windows. Only facts present in those sources are asserted; confirm remediation steps against the current NetApp KB before you act.

Based on the NetApp Knowledge Base and NetApp’s CVE-2026-15308 advisory record. Only claims present in the verified advisory and KB sources are asserted here.

Security AIQUM CVE-2026-15308 2026-10-07

What the advisory says

CVE-2026-15308 carries a CVSS 4.0 base score of 8.7 (High) in NetApp’s advisory record. The scoring vector — AV:N/AC:L/AT:N/PR:N/UI:N/VA:H — describes a network-reachable flaw that needs no privileges and no user interaction, and whose only scored impact is availability: successful exploitation can cause a denial of service. NetApp lists exploitation as public, so proof-of-concept detail is already in circulation. For a management-plane service that is reachable from the network, that combination is enough to put the fix on the calendar.

Who is affected

NetApp’s affected-product list for CVE-2026-15308 sits in the identity and management tier rather than on the storage controllers: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, and Management Services for Element Software and NetApp HCI. If you run AIQUM, inventory that deployment first — the Windows build is the one the new KB guidance targets. ONTAP itself is not on the CVE-2026-15308 affected list; this is a management-plane remediation.

The remediation is a manual Python upgrade

The advisory record for CVE-2026-15308 lists no packaged fix, and the path NetApp documents is a manual Python upgrade. NetApp Knowledge Base published step-by-step guidance titled “How to manually upgrade Python to address CVE-2026-15308 and CVE-2026-11972 in AIQUM 9.18 Windows.” The same article covers a second vulnerability, CVE-2026-11972, on the same Windows platform. Because the fix is applied by hand rather than through a routine package update, your normal patch tooling will not pick it up on its own — it has to be scheduled and tracked deliberately.

First checks for admins

Before scheduling anything, confirm what you actually run and how it is exposed:

What to watch next

Expect NetApp to fold this into a packaged AIQUM update — manual Python upgrades are usually a stopgap — and watch for the CVE-2026-11972 specifics to be documented alongside it. Until then, treat CVE-2026-15308 as a scheduled maintenance item, not a same-day emergency, unless your AIQUM endpoint is internet-exposed. We track the advisory and will update this page if NetApp changes the remediation status.

Sources: NetApp Knowledge Base — “How to manually upgrade Python to address CVE-2026-15308 and CVE-2026-11972 in AIQUM 9.18 Windows” (5 Oct 2026); NetApp advisory record for CVE-2026-15308 (CVSS 4.0 8.7 High; public exploitation).

Sources

NetApp Knowledge Base: how to manually upgrade Python for CVE-2026-15308 / CVE-2026-11972 in AIQUM 9.18 Windows · NetApp advisory record for CVE-2026-15308 (CVSS 4.0 8.7 High; affected: Active IQ Unified Manager for Windows and vSphere; public exploitation).

ONTAP context: ONTAP upgrade process, ONTAP upgrade paths, and security advisories. These explain existing upgrade and security practice; they do not claim a validated fix for CVE-2026-15308.

← Back to the news index