Home / Security / Advisories / NTAP-20260724-0002
NTAP-20260724-0002 — May 2026 GnuTLS Vulnerabilities in NetApp Products
Published 2026-07-24 · Updated 2026-09-21 · Status: Interim · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: Yes
Product family: Active IQ Unified Manager · SolidFire / NetApp HCI · ONTAP · Other NetApp products · NetApp Console / BlueXP | ONTAP-relevant | highest CVSS: 7.5
CVEs in this advisory
- CVE-2026-33845 — HIGH · CVSS 7.5 · site index
- CVE-2026-33846 — HIGH · CVSS 7.5 · site index
- CVE-2026-3833 — MEDIUM · CVSS 6.5 · site index
What the CVE records say
CVE-2026-33845 — A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
CVE-2026-33846 — A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises in merge_handshake_packet() where incoming handshake fragments are matched and merged based solely on handshake type, without validating that the message_length field remains consistent across all fragments of the same logical message. An attacker can exploit this by sending crafted DTLS fragments with conflicting message_length values, causing the implementation to allocate a buffer based on a smaller initial fragment and subsequently write beyond its bounds using larger, inconsistent fragments. Because the merge operation does not enforce proper bounds checking against the allocated buffer size, this results in an out-of-bounds write on the heap. The vulnerability is remotely exploitable without authentication via the DTLS handshake path and can lead to application crashes or potential memory corruption.
CVE-2026-3833 — A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Affected products
- Active IQ Unified Manager for VMware vSphere
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- ONTAP Select Deploy administration utility
- FAS/AFF BIOS - A900/9500
- NetApp Console Agent Container (mysql)
- NetApp Console Agent OVA
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
Official fixes
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026