Critical [CVE-2025-6965] MySQL Server Vulnerability in NetApp Products
This critical-severity NetApp advisory covers CVE-2025-6965 affecting Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere.
Android app · Google Play
Monitor future NetApp CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Multiple NetApp products incorporate MySQL. MySQL versions 8.4.0 through 8.4.7 are susceptible to a vulnerability which when successfully exploited could lead to unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.
Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details. Successful attacks of this vulnerability can result in takeover of MySQL Server.
Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere.
- 8.4.0
- 8.4.7
Official advisory · high-confidence parse· fetched 4 hours ago·verify at source
- Active IQ Unified Manager for Microsoft Windows: 9.18P3
- Active IQ Unified Manager for VMware vSphere: 9.18P3
Official advisory · high-confidence parse· fetched 4 hours ago·verify at source
Mitigation checklist
- Update affected NetApp products to a fixed release: Active IQ Unified Manager for Microsoft Windows: 9.18P3, Active IQ Unified Manager for VMware vSphere: 9.18P3.
- Full Support versions of SnapCenter Server allow MySQL software to be upgraded within documented constraints. Consult the product documentation for supported MySQL versions and other information related to the upgrade. <br><br> In Full Support versions of OnCommand Insight the MySQL software can be upgraded after acquiring updated OnCommand Insight binaries via technical support.
Official advisory · high-confidence parse· fetched 4 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.