Home / Security / Advisories / NTAP-20260429-0005
NTAP-20260429-0005 — April 2026 MySQL Server 8.0.0, 8.4.0 and 9.0.0 Vulnerabilities in NetApp Products
Published 2026-04-29 · Updated 2026-09-01 · Status: Interim · Exploitation: Public · Severity: HIGH 8.8 · ONTAP affected: No — other NetApp product
Product family: Active IQ Unified Manager · OnCommand family · SnapCenter | other NetApp product | highest CVSS: 8.8
CVEs in this advisory
- CVE-2026-35237 · site index
- CVE-2026-21998 · site index
- CVE-2026-35236 · site index
- CVE-2026-34303 · site index
- CVE-2026-35240 · site index
- CVE-2026-35238 · site index
- CVE-2026-35239 · site index
- CVE-2026-22015 · site index
- CVE-2026-22009 · site index
- CVE-2026-22017 · site index
- CVE-2026-22004 · site index
- CVE-2026-34270 · site index
- CVE-2026-34276 · site index
- CVE-2026-34308 · site index
- CVE-2026-22001 · site index
- CVE-2025-14017 · site index
- CVE-2026-22002 · site index
- CVE-2026-34271 · site index
- CVE-2026-22005 · site index
- CVE-2025-15467 — HIGH · CVSS 8.8 · site index
- CVE-2026-34304 · site index
What the CVE records say
CVE-2025-15467 — Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is copied into a fixed-size stack buffer without verifying that its length fits the destination. An attacker can supply a crafted CMS message with an oversized IV, causing a stack-based out-of-bounds write before any authentication or tag verification occurs. Applications and services that parse untrusted CMS or PKCS#7 content using AEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable. Because the overflow occurs prior to authentication, no valid key material is required to trigger it. While exploitability to remote code execution depends on platform and toolchain mitigations, the stack-based write primitive represents a severe risk. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue.
Impact
Successful attacks of this vulnerability can result in takeover, unauthorized read access to a subset of MySQL Server accessible data, and cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. <br><br> Active IQ Unified Manager for Microsoft Windows: <br> Not affected by CVE-2026-34276 or CVE-2026-34271. <br> Active IQ Unified Manager for VMware vSphere: <br> Not affected by CVE-2026-34270, CVE-2026-34276, CVE-2025-14017 or CVE-2026-34271. <br> SnapCenter: <br> Not affected by CVE-2025-15467.
Affected products
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- OnCommand Insight
- SnapCenter
Official fixes
- Active IQ Unified Manager for Microsoft Windows — vendor fix ↗
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- SnapCenter — vendor fix ↗
References
- https://www.oracle.com/security-alerts/cpuapr2026.html#AppendixMSQL ↗
- https://www.oracle.com/security-alerts/cpuapr2026verbose.html#MSQL ↗
- https://www.oracle.com/security-alerts/cpuapr2026.html ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2026