Skip to content
VulniPulse

NetApp Trident / Astra Vulnerabilities & Security Advisories

12 advisories tracked · NetApp Product Security Advisories (PSIRT) · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetApp advisory that VulniPulse classified as Trident / Astra, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 10 high, 1 medium.

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp Trident / Astra advisories

High7.5NetApp

High [CVE-2026-42504] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions through 1.25.9 and 1.26-rc1 through 1.26.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Trident Protect. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-42504
Trident / Astra
Jun 19, 2026
High7.5NetApp

High [CVE-2026-33814] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to 1.25.10 and 1.26.0 prior to 1.26.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, Trident Protect. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-33814
Trident / Astra
Jun 12, 2026
High7.5NetApp

High [CVE-2025-58187] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to 1.24.9 and 1.25.0 prior to 1.25.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, NetApp Console Agent, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-58187
BlueXP / NetApp ConsoleTrident / AstraONTAP tools for VMware
Jun 12, 2026
High7.5NetApp

High [CVE-2026-27137] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions 1.26.0-0 prior to 1.26.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). Affected products: Astra Control Center, Astra Control Center - NetApp Kubernetes Monitoring Operator, Data Infrastructure Insights Telegraf Agent, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-27137
Trident / AstraONTAP tools for VMwareOnCommand / Data Infrastructure InsightsNetApp tools & integrations
May 8, 2026
High7.5NetApp

High [CVE-2026-27142] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to 1.25.8 and 1.26.0-0 prior to 1.26.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, Astra Control Center - NetApp Kubernetes Monitoring Operator, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-27142
Trident / AstraONTAP tools for VMwareNetApp tools & integrations
Apr 22, 2026
High7.5NetApp

High [CVE-2026-25679] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to 1.25.8 and 1.26.0-0 prior to go1.26.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, Astra Control Center - NetApp Kubernetes Monitoring Operator, NetApp Kubernetes Monitoring Operator, ONTAP tools for VMware vSphere 10, Trident, Trident Protect. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-25679
Trident / AstraONTAP tools for VMwareNetApp tools & integrations
Apr 22, 2026
High7.5NetApp

High [CVE-2025-61726] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to 1.24.12 and 1.25.0 prior to 1.25.6 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, NetApp Console Agent, ONTAP tools for VMware vSphere 10, Trident Protect. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-61726
BlueXP / NetApp ConsoleTrident / AstraONTAP tools for VMware
Mar 11, 2026
High7.5NetApp

High [CVE-2025-61729] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to 1.24.11 and 1.25.0 prior to 1.25.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Astra Control Center, Data Infrastructure Insights Telegraf Agent, NetApp Console Agent, ONTAP tools for VMware vSphere 10, Trident. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-61729
BlueXP / NetApp ConsoleTrident / AstraONTAP tools for VMwareOnCommand / Data Infrastructure Insights
Jan 30, 2026
High7.3NetApp

High [CVE-2025-52881] Runc Vulnerability in NetApp Products

Multiple NetApp products incorporate runc. Runc versions prior to 1.2.8, prior to 1.3.3, and prior to 1.4.0-rc.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Astra Control Center, NetApp Console Agent, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-52881
BlueXP / NetApp ConsoleTrident / AstraONTAP tools for VMware
Nov 21, 2025
High7.3NetApp

High [CVE-2025-31133] Runc Vulnerability in NetApp Products

Multiple NetApp products incorporate runc. Runc versions prior to 1.2.8, prior to 1.3.3, and prior to 1.4.0-rc.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Astra Control Center, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-31133
Trident / AstraONTAP tools for VMware
Nov 21, 2025

← All NetApp advisories