CVE Tools

Netapp

2,107 CVEs tracked since 2008. Since Sep 2019, 25 of them reached CISA KEV.

Netapp CVEs per month

Sep 2019 to Sep 2025. Point at a month, or focus the strip and use the arrow keys.
Netapp CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-09200
2019-10601
2019-11280
2019-12250
2020-01350
2020-02161
2020-03170
2020-04null or fewer
2020-05null or fewer
2020-06310
2020-07null or fewer
2020-08130
2020-0990
2020-10580
2020-11311
2020-12340
2021-01721
2021-02240
2021-03null or fewer
2021-04550
2021-05490
2021-06390
2021-07501
2021-08351
2021-09171
2021-101022
2021-11140
2021-12271
2022-011051
2022-02481
2022-03502
2022-04610
2022-05370
2022-06280
2022-07490
2022-08290
2022-09190
2022-10470
2022-11180
2022-12110
2023-01null or fewer
2023-02110
2023-03null or fewer
2023-04321
2023-05150
2023-06140
2023-07350
2023-08170
2023-0962
2023-10423
2023-11null or fewer
2023-12null or fewer
2024-01221
2024-02240
2024-03130
2024-04450
2024-05100
2024-06null or fewer
2024-07201
2024-0840
2024-0950
2024-1080
2024-1150
2024-1260
2025-0151
2025-02130
2025-03102
2025-0450
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-0940

Products

The products that kept showing up in Netapp's monthly top three, with their CVEs summed over those months.

  1. Oncommand Insight55619 months
  2. Active Iq Unified Manager48432 months
  3. Oncommand Workflow Automation36611 months
  4. Snapcenter2379 months
  5. H410S Firmware13913 months
  6. H700S Firmware12212 months
  7. Cloud Backup11711 months
  8. H300S Firmware1049 months
  9. Steelstore Cloud Integrated Storage777 months
  10. H500S Firmware457 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Netapp.

  1. CVE-2026-22056CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)—
  2. CVE-2026-22049ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited coul...8.8
  3. CVE-2026-22055Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.8.8
  4. CVE-2026-22054Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.8.8
  5. CVE-2026-22051StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attac...4.3
  6. CVE-2026-22052ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the co...—
  7. CVE-2026-22048StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptib...7.1
  8. CVE-2026-22050ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snaps...4.3
  9. CVE-2025-26517CVE-2025-26517 Privilege Escalation Vulnerability in StorageGRID (formerly StorageGRID Webscale)5.4
  10. CVE-2025-26516CVE-2025-26516 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)5.3
  11. CVE-2025-26515CVE-2025-26515 Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Webscale)7.5
  12. CVE-2025-26514CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale)6.4
  13. CVE-2025-26513The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges.7.0
  14. CVE-2025-27820Apache HttpComponents: PSL (Public Suffix List) validation bypass7.5
  15. CVE-2025-30722Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit ...5.3

The record

Peak rank
#3 in Oct 2021
Busiest month shown
Jan 2022, 105 CVEs
Months with a KEV entry
19 since Sep 2019
Monthly snapshots
90 since 2008
Netapp's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store