Home / Security Hub

NetApp ONTAP Security Hub

A living, machine-compiled index of NetApp security advisories, ONTAP-relevant CVEs, and known-exploited vulnerabilities — pulled automatically from official sources so you can check "is my cluster affected?" fast.

Not the source of truth. Data is summarized from security.netapp.com, the NVD, and CISA KEV. Always open the linked official advisory before acting.
751
ONTAP advisories
1669
CVEs indexed
0
Known exploited
3
Official sources

Latest ONTAP advisories

AdvisoryPublishedTitleStatusExploitationCVEs
NTAP-20260327-00112026-03-27CVE-2026-23949 Jaraco.Context Vulnerability in NetApp ProductsInterimPublicCVE-2026-23949
NTAP-20251121-00022025-11-21CVE-2025-52565 Runc Vulnerability in NetApp ProductsInterimPublicCVE-2025-52565
NTAP-20260724-00022026-07-24May 2026 GnuTLS Vulnerabilities in NetApp ProductsInterimPublicCVE-2026-33845, CVE-2026-33846, CVE-2026-3833
NTAP-20260320-00132026-03-20CVE-2026-23231 Linux Kernel Vulnerability in NetApp ProductsInterimPublicCVE-2026-23231
NTAP-20260116-00052026-01-16CVE-2025-64506 Libpng Vulnerability in NetApp ProductsInterimPublicCVE-2025-64506
NTAP-20250912-00122025-09-12CVE-2025-8885 Bouncy Castle Vulnerability in NetApp ProductsInterimPublicCVE-2025-8885
NTAP-20260717-00122026-07-17July 2026 OpenSSH Vulnerabilities in NetApp ProductsInterimPublicCVE-2026-59995, CVE-2026-59996, CVE-2026-59997
NTAP-20260617-00042026-06-17CVE-2026-42764 OpenSSL Vulnerability in NetApp ProductsInterimPublicCVE-2026-42764
NTAP-20260422-00052026-04-22CVE-2026-33186 gRPC-Go Vulnerability in NetApp ProductsInterimPublicCVE-2026-33186
NTAP-20260703-00202026-07-03CVE-2026-55200 Libssh2 Vulnerability in NetApp ProductsInterimPublicCVE-2026-55200

All 751 advisories have detail pages — see the CVE index or the rolling 30-day digest.

Latest ONTAP-relevant CVEs

CVEPublishedSeverityCVSSSummary
CVE-2026-660332026-07-24HIGH7.5libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability
CVE-2026-660322026-07-24HIGH8.8libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() funct
CVE-2026-220492026-07-22HIGH8.8ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to
CVE-2026-600022026-07-08HIGH7.7ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchan
CVE-2026-600012026-07-08MEDIUM6.5sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-600002026-07-08LOW3.7sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from ex
CVE-2026-599992026-07-08MEDIUM5.9In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, b
CVE-2026-599982026-07-08MEDIUM4.8sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no v
CVE-2026-599972026-07-08MEDIUM4.2internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be
CVE-2026-599962026-07-08MEDIUM4.2scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occ

Browse the full CVE index (1669 CVEs) →

Known exploited (CISA KEV)

CVEAddedProductName
No NetApp products currently on the CISA KEV list.

Sources

Subscribe to the advisory RSS feed ↗

Generated 2026-08-25 · unofficial community resource.