Home / Security Hub
NetApp ONTAP Security Hub
A living, machine-compiled index of NetApp security advisories, ONTAP-relevant CVEs, and known-exploited vulnerabilities — pulled automatically from official sources so you can check "is my cluster affected?" fast.
Not the source of truth. Data is summarized from security.netapp.com, the NVD, and CISA KEV. Always open the linked official advisory before acting.
751
ONTAP advisories
1669
CVEs indexed
0
Known exploited
3
Official sources
Latest ONTAP advisories
| Advisory | Published | Title | Status | Exploitation | CVEs |
|---|---|---|---|---|---|
NTAP-20260327-0011 | 2026-03-27 | CVE-2026-23949 Jaraco.Context Vulnerability in NetApp Products | Interim | Public | CVE-2026-23949 |
NTAP-20251121-0002 | 2025-11-21 | CVE-2025-52565 Runc Vulnerability in NetApp Products | Interim | Public | CVE-2025-52565 |
NTAP-20260724-0002 | 2026-07-24 | May 2026 GnuTLS Vulnerabilities in NetApp Products | Interim | Public | CVE-2026-33845, CVE-2026-33846, CVE-2026-3833 |
NTAP-20260320-0013 | 2026-03-20 | CVE-2026-23231 Linux Kernel Vulnerability in NetApp Products | Interim | Public | CVE-2026-23231 |
NTAP-20260116-0005 | 2026-01-16 | CVE-2025-64506 Libpng Vulnerability in NetApp Products | Interim | Public | CVE-2025-64506 |
NTAP-20250912-0012 | 2025-09-12 | CVE-2025-8885 Bouncy Castle Vulnerability in NetApp Products | Interim | Public | CVE-2025-8885 |
NTAP-20260717-0012 | 2026-07-17 | July 2026 OpenSSH Vulnerabilities in NetApp Products | Interim | Public | CVE-2026-59995, CVE-2026-59996, CVE-2026-59997 |
NTAP-20260617-0004 | 2026-06-17 | CVE-2026-42764 OpenSSL Vulnerability in NetApp Products | Interim | Public | CVE-2026-42764 |
NTAP-20260422-0005 | 2026-04-22 | CVE-2026-33186 gRPC-Go Vulnerability in NetApp Products | Interim | Public | CVE-2026-33186 |
NTAP-20260703-0020 | 2026-07-03 | CVE-2026-55200 Libssh2 Vulnerability in NetApp Products | Interim | Public | CVE-2026-55200 |
All 751 advisories have detail pages — see the CVE index or the rolling 30-day digest.
Latest ONTAP-relevant CVEs
| CVE | Published | Severity | CVSS | Summary |
|---|---|---|---|---|
CVE-2026-66033 | 2026-07-24 | HIGH | 7.5 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability |
CVE-2026-66032 | 2026-07-24 | HIGH | 8.8 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() funct |
CVE-2026-22049 | 2026-07-22 | HIGH | 8.8 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to |
CVE-2026-60002 | 2026-07-08 | HIGH | 7.7 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchan |
CVE-2026-60001 | 2026-07-08 | MEDIUM | 6.5 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. |
CVE-2026-60000 | 2026-07-08 | LOW | 3.7 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from ex |
CVE-2026-59999 | 2026-07-08 | MEDIUM | 5.9 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, b |
CVE-2026-59998 | 2026-07-08 | MEDIUM | 4.8 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no v |
CVE-2026-59997 | 2026-07-08 | MEDIUM | 4.2 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be |
CVE-2026-59996 | 2026-07-08 | MEDIUM | 4.2 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occ |
Browse the full CVE index (1669 CVEs) →
Known exploited (CISA KEV)
| CVE | Added | Product | Name |
|---|---|---|---|
| No NetApp products currently on the CISA KEV list. | |||
Sources
- NetApp Security Advisories — official NTAP advisories (refreshed daily)
- NVD — CVE records, CVSS scores, references
- CISA KEV — vulnerabilities known to be exploited in the wild
- Community context: r/netapp, NetApp Community
Subscribe to the advisory RSS feed ↗
Generated 2026-08-25 · unofficial community resource.