Home / Security / ONTAP CVE Index
ONTAP CVE Index
8,510 CVEs referenced by NetApp advisories. The index is split by year so you never download the whole database at once — pick a year below, or jump straight to the most recent records.
Always verify. Severity and CVSS come from the NVD record; NetApp's advisory is authoritative for affected versions and fixes.
Jump to a year
1,058
2026 CVEs
755
2025 CVEs
676
2024 CVEs
878
2023 CVEs
889
2022 CVEs
924
2021 CVEs
895
2020 CVEs
858
2019 CVEs
469
2018 CVEs
333
2017 CVEs
329
2016 CVEs
267
2015 CVEs
135
2014 CVEs
9
2013 CVEs
4
2012 CVEs
4
2011 CVEs
5
2010 CVEs
1
2009 CVEs
3
2008 CVEs
4
2007 CVEs
2
2006 CVEs
2
2005 CVEs
3
2004 CVEs
3
2003 CVEs
2
2002 CVEs
2
1999 CVEs
15 most recent CVEs
| CVE | Published | Severity | CVSS | Summary / Sources |
|---|---|---|---|---|
CVE-2026-22061 | 2026-10-09 | HIGH | 8.2 | Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS NVD ↗ · NTAP-20261009-0026 |
CVE-2026-93546 | 2026-10-01 | HIGH | 8.8 | Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persis NVD ↗ · NTAP-20261007-0004 |
CVE-2026-79768 | 2026-10-01 | MEDIUM | 5.3 | Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir direc NVD ↗ · NTAP-20261007-0018 |
CVE-2026-73637 | 2026-10-01 | HIGH | 7.3 | Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cau NVD ↗ · NTAP-20261007-0016 |
CVE-2026-73636 | 2026-10-01 | HIGH | 8.1 | Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (M NVD ↗ · NTAP-20261007-0005 |
CVE-2026-63718 | 2026-10-01 | HIGH | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and NVD ↗ · NTAP-20261007-0015 |
CVE-2026-63686 | 2026-10-01 | HIGH | 7.5 | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to NVD ↗ · NTAP-20261007-0014 |
CVE-2026-63292 | 2026-10-01 | HIGH | 7.5 | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause NVD ↗ · NTAP-20261007-0013 |
CVE-2026-63045 | 2026-10-01 | HIGH | 7.5 | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forwa NVD ↗ · NTAP-20261007-0012 |
CVE-2026-59797 | 2026-10-01 | CRITICAL | 9.8 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: NVD ↗ · NTAP-20261007-0003 |
CVE-2026-59685 | 2026-10-01 | HIGH | 7.5 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache NVD ↗ · NTAP-20261007-0011 |
CVE-2026-58415 | 2026-10-01 | MEDIUM | 5.3 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remot NVD ↗ · NTAP-20261007-0017 |
CVE-2026-57941 | 2026-10-01 | CRITICAL | 9.8 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2 NVD ↗ · NTAP-20261007-0002 |
CVE-2026-56449 | 2026-10-01 | HIGH | 7.5 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 th NVD ↗ · NTAP-20261007-0010 |
CVE-2026-56154 | 2026-10-01 | CRITICAL | 9.8 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 throu NVD ↗ · NTAP-20261007-0001 |
Known exploited (CISA KEV)
| CVE | Added | Product | Name |
|---|---|---|---|
| No NetApp products currently on the CISA KEV list. | |||
Rolling advisory digest → · Security RSS feed · Security hub
Generated 2026-10-10 · unofficial community resource.