Skip to content
VulniPulse

NetApp Active IQ Unified Manager Vulnerabilities & Security Advisories

81 advisories tracked · NetApp Product Security Advisories (PSIRT) · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetApp advisory that VulniPulse classified as Active IQ Unified Manager, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 10 critical, 43 high, 25 medium, 4 low.

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp Active IQ Unified Manager advisories

High7.5NetApp

High [CVE-2026-3039] ISC BIND Vulnerability in NetApp Products

Multiple NetApp products incorporate ISC BIND. ISC BIND versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, and 9.21.0 through 9.21.21 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-3039
Active IQ Unified Manager
May 29, 2026
Medium5.3NetApp

Medium [CVE-2026-5950] ISC BIND Vulnerability in NetApp Products

Multiple NetApp products incorporate ISC BIND. ISC BIND versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, and 9.21.7 through 9.21.21 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5950
Active IQ Unified Manager
May 29, 2026
Medium5.3NetApp

Medium [CVE-2026-3592] ISC BIND Vulnerability in NetApp Products

Multiple NetApp products incorporate ISC BIND. ISC BIND versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, and 9.21.0 through 9.21.21 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-3592
Active IQ Unified Manager
May 29, 2026
Medium6.5NetApp

Medium [CVE-2026-5545] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.10.6 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5545
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
May 15, 2026
Medium5.0NetApp

Medium [CVE-2026-5450] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C Library (glibc). Glibc versions 2.7 through 2.43 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5450
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
May 13, 2026
Medium5.9NetApp

Medium [CVE-2026-5435] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C Library (glibc). Glibc versions 2.2 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5435
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
May 13, 2026
High8.3NetApp

High [CVE-2026-0603] Hibernate ORM Vulnerability in NetApp Products

Multiple NetApp products incorporate Hibernate ORM. Hibernate ORM versions 5.2.8 through 5.6.15 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-0603
Active IQ Unified ManagerONTAP tools for VMware
May 8, 2026
Critical9.8NetApp

Critical [CVE-2025-14017 +20] April 2026 MySQL Server 8.0.0, 8.4.0 and 9.0.0 Vulnerabilities in NetApp Products

Multiple NetApp products incorporate MySQL. MySQL versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are susceptible to a vulnerability that could allow unauthenticated attacker with logon to the infrastructure, unauthorized creation, deletion or modification access to critical data or complete access to all MySQL Server accessible data, unauthenticated attacker or low or high privileged attacker with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - April 2026” for additional details. MySQL versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are susceptible to a vulnerability that could allow an attacker to create, delete, or modify critical data, or potentially gain full access to all data accessible by the MySQL Server. Successful attacks of this vulnerability can result in takeover, unauthorized read access to a subset of MySQL Server accessible data, and cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Active IQ Unified Manager for Microsoft Windows: Not affected by CVE-2026-34276 or CVE-2026-34271. Active IQ Unified Manager for VMware vSphere: SnapCenter: Not affected by CVE-2025-15467. Affected products named by the advisory: OnCommand Insight.

CVE-2025-14017CVE-2025-15467CVE-2026-21998+18
SnapCenterActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Apr 29, 2026
High7.5NetApp

High [CVE-2026-4046] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C Library (glibc). Glibc versions through 2.43 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-4046
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerONTAP tools for VMware
Apr 22, 2026
High7.5NetApp

High [CVE-2026-35385] OpenSSH Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions prior to 10.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-35385
Active IQ Unified ManagerONTAP tools for VMware
Apr 17, 2026
Medium6.5NetApp

Medium [CVE-2026-1965] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.10.6 prior to 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP 9, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-1965
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Mar 27, 2026
Medium6.5NetApp

Medium [CVE-2026-3784] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.7 prior to 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP 9, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-3784
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Mar 27, 2026
Medium5.3NetApp

Medium [CVE-2026-3783] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.33.0 prior to 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-3783
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Mar 27, 2026
Medium5.3NetApp

Medium [CVE-2025-14524] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate libcurl. Libcurl versions 7.33.0 through 8.17.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-14524
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Feb 13, 2026
High7.5NetApp

High [CVE-2026-21925 +3] January 2026 Java Platform Standard Edition Vulnerabilities in NetApp Products

Multiple NetApp products incorporate the Oracle Java Platform, Standard Edition (Java SE). Java SE versions 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1 are susceptible to vulnerabilities that could allow an unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data as well as unauthorized read access to a subset of Oracle Java SE accessible data, unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data, and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. OnCommand Insight: Affected by only CVE-2026-21925 and CVE-2026-21933. Data Infrastructure Insights Storage Workload Security Agent: NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights and Data Secure Storage Workload Security Agent; NetApp Console Agent.

CVE-2026-21925CVE-2026-21932CVE-2026-21933+1
Active IQ Unified ManagerBlueXP / NetApp ConsoleOnCommand / Data Infrastructure Insights
Jan 23, 2026
High7.5NetApp

High [CVE-2025-9230 +6] January 2026 MySQL Server Vulnerabilities in NetApp Products

Multiple NetApp products incorporate MySQL. MySQL versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7, and 9.0.0 through 9.5.0 are susceptible to a vulnerability that could allow unauthenticated, high and low privileged attackers with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight, SnapCenter.

CVE-2025-9230CVE-2026-21936CVE-2026-21937+4
SnapCenterActive IQ Unified ManagerOnCommand / Data Infrastructure Insights
Jan 23, 2026
High7.5NetApp

High [CVE-2025-38732] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, E-Series SANtricity OS Controller Software, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-38732
ONTAPSANtricityActive IQ Unified ManagerONTAP Select
Jan 23, 2026
Medium5.5NetApp

Medium [CVE-2025-40027] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-40027
ONTAPActive IQ Unified ManagerONTAP Select
Jan 23, 2026
Medium5.5NetApp

Medium [CVE-2025-38465] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70, AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50, Active IQ Unified Manager for VMware vSphere, FAS/AFF Baseboard Management Controller (BMC) - A320, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, FAS/AFF Service Processor - A300/8200, FAS/AFF Service Processor - A700/9000, NetApp HCI Baseboard Management Controller (BMC) - H610S, SnapCenter Plug-in for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-38465
AFF / ASA / FASElement SoftwareSnapCenterActive IQ Unified Manager
Jan 21, 2026
High7.5NetApp

High [CVE-2024-25062] Libxml2 Vulnerability in NetApp Products

Multiple NetApp products incorporate libxml2. libxml2 versions prior to 2.11.7 and 2.12.0 prior to 2.12.5 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-25062
ONTAPActive IQ Unified Manager
Jan 16, 2026

← All NetApp advisories