Skip to content
VulniPulse

NetApp E-Series / SANtricity Vulnerabilities & Security Advisories

16 advisories tracked · NetApp Product Security Advisories (PSIRT) · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetApp advisory that VulniPulse classified as E-Series / SANtricity, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 7 high, 6 medium, 2 low.

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp E-Series / SANtricity advisories

Medium6.8NetApp

Medium [CVE-2026-60589 +2] August 2026 Java SE Vulnerabilities in NetApp Products

Java SE versions 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, and 26.0.2 are susceptible to vulnerabilities that allow unauthenticated attackers with network access via multiple protocols (including HTTP and TLS) to compromise Oracle Java SE. Refer to “Oracle Critical Security Patch Update Advisory - August 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized access to critical data or complete access to all Oracle Java SE accessible data or unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Data Infrastructure Insights and Data Secure Storage Workload Security Agent, E-Series SANtricity OS Controller Software, E-Series SANtricity Unified Manager and Web Services Proxy, OnCommand Insight, SANtricity Storage Plugin for vCenter. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-60589CVE-2026-61308CVE-2026-70907
SANtricityActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Aug 21, 2026
Medium5.9NetApp

Medium [CVE-2026-31790] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31790
AFF / ASA / FASSANtricityElement Software
Apr 17, 2026
Medium6.5NetApp

Medium [CVE-2026-4437 +1] March 2026 GNU C Library (glibc) Vulnerabilities in NetApp Products

Multiple NetApp products incorporate GNU C Library. GNU C Library (glibc) versions 2.34 through 2.43 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Active IQ Unified Manager for VMware vSphere: Affected only by CVE-2026-4437. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H610S.

CVE-2026-4437CVE-2026-4438
AFF / ASA / FASSANtricityElement SoftwareActive IQ Unified Manager
Apr 10, 2026
Medium5.5NetApp

Medium [CVE-2024-26733] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70, E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - A320, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, FAS/AFF Service Processor - A300/8200, FAS/AFF Service Processor - A700/9000, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-26733
AFF / ASA / FASSANtricityElement SoftwareFAS2720
Nov 1, 2024
Medium4.4NetApp

Medium [CVE-2024-42154] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, Active IQ Unified Manager for VMware vSphere, E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), ONTAP Select Deploy administration utility, ONTAP tools for VMware vSphere 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-42154
AFF / ASA / FASSANtricityElement SoftwareActive IQ Unified Manager
Aug 28, 2024
Medium5.3NetApp Updated

Medium [CVE-2023-26048 +1] April 2023 Eclipse Jetty Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Eclipse Jetty. Eclipse Jetty versions through 9.4.50, through 10.0.13, through 11.0.13, and through 12.0.0.alpha3 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, E-Series SANtricity OS Controller Software, E-Series SANtricity Unified Manager and Web Services Proxy, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2023-26048CVE-2023-26049
SANtricityElement SoftwareActive IQ Unified Manager
May 26, 2023

← All NetApp advisories