Skip to content
VulniPulse

NetApp Security Advisories & CVEs

417 advisories tracked · NetApp Product Security Advisories (PSIRT) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your NetApp device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetApp's recent advisories.

Official source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp advisories

High7.5NetApp

High [CVE-2026-54225] Apache CXF Vulnerability in NetApp Products

Apache CXF versions prior to 3.6.12, 4.0.0 prior to 4.1.8, and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: SnapCenter. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-54225
SnapCenter
Sep 11, 2026
High7.5NetApp

High [CVE-2026-65432] Apache CXF Vulnerability in NetApp Products

Apache CXF prior to 3.6.12, 4.0.0 prior to 4.1.8, and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-65432
Unclassified
Sep 11, 2026
High7.5NetApp

High [CVE-2026-68481] Apache CXF Vulnerability in NetApp Products

Apache CXF versions prior to 3.6.12, 4.0.0 prior to 4.1.8, and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-68481
Unclassified
Sep 11, 2026
High7.8NetApp

High [CVE-2024-27012] Linux Kernel Vulnerability in NetApp Products

Certain Linux kernel versions are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-27012
AFF / ASA / FASElement Software
Sep 11, 2026
High8.1NetApp

High [CVE-2026-41855] Spring Framework Vulnerability in NetApp Products

Spring Framework versions prior to 6.2.19 and 7.0.0-m1 prior to 7.0.8 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-41855
Unclassified
Sep 11, 2026
High7.2NetApp

High [CVE-2026-6471] PostgreSQL Vulnerability in NetApp Products

PostgreSQL versions prior to 18.6, 17.11, 16.15, 15.19 and 14.24 are susceptible to a vulnerability referred to as PostGREShell which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6471
Unclassified
Sep 11, 2026
High8.1NetApp

High [CVE-2026-57817] Apache CXF Vulnerability in NetApp Products

Apache CXF versions 4.2.0 prior to 4.2.3, 4.0.0 prior to 4.1.8, prior to 3.6.12 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-57817
Unclassified
Sep 11, 2026
High7.8NetApp

High [CVE-2026-23066] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions 4.11 prior to 6.18.8 and 6.19-rc1 through 6.19-c6 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-23066
ONTAP tools for VMware
Sep 11, 2026
High8.1NetApp

High [CVE-2026-57818] Apache CXF Vulnerability in NetApp Products

Apache CXF versions prior to 3.6.12, 4.0.0 prior to 4.1.8, and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-57818
Unclassified
Sep 11, 2026
High7.5NetApp

High [CVE-2026-64958] Apache CXF Vulnerability in NetApp Products

Apache CXF versions prior to 3.6.12, 4.0.0 prior to 4.1.78 and 4.2.0 prior to 4.2.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: SnapCenter. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-64958
SnapCenter
Sep 11, 2026
High7.8NetApp Exploited CISA KEV

High [CVE-2026-53362] Linux Kernel Vulnerability in NetApp Products

Linux kernel versions 6.0-rc1 through 6.1.176, 6.13-rc1 through 6.18.37, 6.19-rc1 through 7.1.2, 6.2-rc1 through 6.6.143, and 6.7-rc1 through 6.12.94 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-53362
Unclassified
Sep 3, 2026
High7.8NetApp

High [CVE-2026-58091] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user to escalate their privileges. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-58091
Unclassified
Sep 3, 2026
High8.8NetApp

High [CVE-2026-58095 +2] August 2026 FreeBSD Point-to-Point Protocol Vulnerabilities in NetApp Products

All supported versions of FreeBSD are susceptible to vulnerabilities in Point-to-Point Protocol (PPP) which when successfully exploited could allow a malicious PPP peer (CVE-2026-58095 or CVE-2026-58096) or a local user with access to the ppp(8) command interface (CVE-2026-58097) to crash ppp(8) or potentially execute arbitrary code as root. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-58095CVE-2026-58096CVE-2026-58097
Unclassified
Sep 3, 2026
High7.8NetApp

High [CVE-2026-58090] FreeBSD Vulnerability in NetApp Products

FreeBSD versions 15.0 and later are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user to escalate privileges. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-58090
Unclassified
Sep 3, 2026
High7.8NetApp

High [CVE-2026-58089] FreeBSD Vulnerability in NetApp Products

All supported versions of FreeBSD are susceptible to a vulnerability which when successfully exploited could allow an unprivileged local user who has attached PMCs to a process to continue monitoring it after the process executes a setuid or setgid binary. Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-58089
Unclassified
Sep 3, 2026
High8.2NetApp

High [CVE-2026-11972] Python Vulnerability in NetApp Products

Python versions 2.3 through 3.10.20, 3.11.0a1 through 3.11.15, 3.12.0a1 through 3.12.13, 3.13.0a1 through 3.13.14, 3.14.0a1 through 3.14.6, and 3.15.0a1 through 3.15.0b3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-11972
Element SoftwareActive IQ Unified Manager
Sep 3, 2026
High8.1NetApp

High [CVE-2026-58092] FreeBSD Vulnerability in NetApp Products

FreeBSD versions 15.0 and later are susceptible to a vulnerability which when successfully exploited could allow certain mac_do rules to be abused to set a process' group ID to 0. Successful exploitation of this vulnerability could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-58092
Unclassified
Sep 3, 2026
High7.5NetApp

High [CVE-2026-63072] OpenSSL Vulnerability in NetApp Products

OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, and 1.1.1 are susceptible to a vulnerability which when successfully exploited could allow an attacker who supplies a crafted CMS message to trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-63072
Unclassified
Sep 2, 2026
High8.1NetApp

High [CVE-2026-68569] Apache Tomcat Vulnerability in NetApp Products

Apache Tomcat versions 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.0.M1 through 9.0.120, 8.5.0 through 8.5.100 (EOL), and 7.0.0 through 7.0.109 (EOL) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-68569
Unclassified
Sep 2, 2026
High7.5NetApp

High [CVE-2026-66299] Apache Tomcat Vulnerability in NetApp Products

Apache Tomcat versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-66299
Unclassified
Sep 2, 2026

← All vendors