Skip to content
VulniPulse

NetApp Security Advisories & CVEs

286 advisories tracked · NetApp Product Security Advisories (PSIRT) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your NetApp device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetApp's recent advisories.

Official source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp advisories

Medium6.5NetApp

Medium [CVE-2026-5545] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.10.6 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5545
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
May 15, 2026
Medium5.9NetApp

Medium [CVE-2026-6253] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.14.1 through 8.19.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-6253
AFF / ASA / FASElement Software
May 15, 2026
Medium6.3NetApp

Medium [CVE-2026-34477] Apache Log4j Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Log4j. Apache Log4j versions 2.12.0 through 2.25.3 and 3.0.0-alpha1 through 3.0.0-beta3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-34477
Unclassified
May 13, 2026
Medium6.9NetApp

Medium [CVE-2026-34480] Apache Log4j Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Log4j. Apache Log4j versions 2.0-alpha1 through 2.25.3 and 3.0.0-alpha1 through 3.0.0-beta3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-34480
Unclassified
May 13, 2026
Medium5.0NetApp

Medium [CVE-2026-5450] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C Library (glibc). Glibc versions 2.7 through 2.43 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5450
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
May 13, 2026
Medium5.9NetApp

Medium [CVE-2026-5435] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C Library (glibc). Glibc versions 2.2 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5435
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
May 13, 2026
Medium6.5NetApp

Medium [CVE-2026-33523] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions 2.4.0 through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). ONTAP 9: Affected in 9.18.1 and higher. NetApp states there is no workaround available at this time.

CVE-2026-33523
Unclassified
May 8, 2026
Medium4.8NetApp

Medium [CVE-2026-33006] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2026-33006
Unclassified
May 8, 2026
Medium5.5NetApp

Medium [CVE-2026-24072] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. NetApp states there is no workaround available at this time.

CVE-2026-24072
Unclassified
May 8, 2026
Medium5.3NetApp

Medium [CVE-2026-33007] Apache HTTP Server Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache HTTP Server. Apache HTTP Server versions 2.4.0 through 2.4.66 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2026-33007
Unclassified
May 8, 2026
Medium6.5NetApp

Medium [CVE-2026-0964 +4] February 2026 Libssh Vulnerabilities in NetApp Products

Multiple NetApp products incorporate libssh. Libssh versions through 0.11.3 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-0964CVE-2026-0965CVE-2026-0966+2
ONTAP tools for VMware
May 1, 2026
Medium4.9NetApp

Medium [CVE-2026-34267 +2] April 2026 MySQL Server 8.0.0 Vulnerabilities in NetApp Products

Multiple NetApp products incorporate MySQL. MySQL versions 8.0.0 through 8.0.45 are susceptible to a vulnerability that could allow a high privileged attacker with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - April 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2026-34267CVE-2026-34278CVE-2026-34293
Active IQ Unified ManagerOnCommand / Data Infrastructure Insights
Apr 29, 2026
Medium6.6NetApp Updated

Medium [CVE-2025-46836] net-tools Vulnerability in NetApp Products

net-tools versions through 2.10 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-46836
Unclassified
Apr 29, 2026
Medium5.5NetApp

Medium [CVE-2026-23095] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux Kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-23095
AFF / ASA / FASElement Software
Apr 24, 2026
Medium6.4NetApp

Medium [CVE-2026-22998] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux Kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-22998
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Apr 24, 2026
Medium5.0NetApp

Medium [CVE-2026-5704] Tar Vulnerability in NetApp Products

Multiple NetApp products incorporate Tar. Tar is susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: NetApp Console Agent Container (cbs_catalog), NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-5704
AFF / ASA / FASElement SoftwareBlueXP / NetApp Console
Apr 24, 2026
Medium5.4NetApp

Medium [CVE-2025-66168] Apache ActiveMQ Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache ActiveMQ. Apache ActiveMQ versions 6.2.0 prior to 6.2.4, 6.0.0 through 6.1.8, and prior to 5.19.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp states there is no workaround available at this time.

CVE-2025-66168
Unclassified
Apr 22, 2026
Medium5.9NetApp

Medium [CVE-2026-31790] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31790
AFF / ASA / FASSANtricityElement Software
Apr 17, 2026
Medium5.9NetApp

Medium [CVE-2026-28389] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-28389
AFF / ASA / FASElement Software
Apr 17, 2026
Medium5.8NetApp

Medium [CVE-2026-31789] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. Certain versions of OpenSSL are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp LOADER 8.x. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2026-31789
AFF / ASA / FASElement SoftwareNetApp tools & integrations
Apr 17, 2026

← All vendors