Netapp
2,107 CVEs tracked since 2008. Since Sep 2019, 25 of them reached CISA KEV.
Netapp CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2019-09 | 20 | 0 |
| 2019-10 | 60 | 1 |
| 2019-11 | 28 | 0 |
| 2019-12 | 25 | 0 |
| 2020-01 | 35 | 0 |
| 2020-02 | 16 | 1 |
| 2020-03 | 17 | 0 |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | 31 | 0 |
| 2020-07 | null or fewer | |
| 2020-08 | 13 | 0 |
| 2020-09 | 9 | 0 |
| 2020-10 | 58 | 0 |
| 2020-11 | 31 | 1 |
| 2020-12 | 34 | 0 |
| 2021-01 | 72 | 1 |
| 2021-02 | 24 | 0 |
| 2021-03 | null or fewer | |
| 2021-04 | 55 | 0 |
| 2021-05 | 49 | 0 |
| 2021-06 | 39 | 0 |
| 2021-07 | 50 | 1 |
| 2021-08 | 35 | 1 |
| 2021-09 | 17 | 1 |
| 2021-10 | 102 | 2 |
| 2021-11 | 14 | 0 |
| 2021-12 | 27 | 1 |
| 2022-01 | 105 | 1 |
| 2022-02 | 48 | 1 |
| 2022-03 | 50 | 2 |
| 2022-04 | 61 | 0 |
| 2022-05 | 37 | 0 |
| 2022-06 | 28 | 0 |
| 2022-07 | 49 | 0 |
| 2022-08 | 29 | 0 |
| 2022-09 | 19 | 0 |
| 2022-10 | 47 | 0 |
| 2022-11 | 18 | 0 |
| 2022-12 | 11 | 0 |
| 2023-01 | null or fewer | |
| 2023-02 | 11 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 32 | 1 |
| 2023-05 | 15 | 0 |
| 2023-06 | 14 | 0 |
| 2023-07 | 35 | 0 |
| 2023-08 | 17 | 0 |
| 2023-09 | 6 | 2 |
| 2023-10 | 42 | 3 |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | 22 | 1 |
| 2024-02 | 24 | 0 |
| 2024-03 | 13 | 0 |
| 2024-04 | 45 | 0 |
| 2024-05 | 10 | 0 |
| 2024-06 | null or fewer | |
| 2024-07 | 20 | 1 |
| 2024-08 | 4 | 0 |
| 2024-09 | 5 | 0 |
| 2024-10 | 8 | 0 |
| 2024-11 | 5 | 0 |
| 2024-12 | 6 | 0 |
| 2025-01 | 5 | 1 |
| 2025-02 | 13 | 0 |
| 2025-03 | 10 | 2 |
| 2025-04 | 5 | 0 |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | 4 | 0 |
Products
The products that kept showing up in Netapp's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Netapp.
- CVE-2026-22056CVE-2026-22056 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)—
- CVE-2026-22049ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited coul...8.8
- CVE-2026-22055Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.8.8
- CVE-2026-22054Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.8.8
- CVE-2026-22051StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attac...4.3
- CVE-2026-22052ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the co...—
- CVE-2026-22048StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use Microsoft Entra ID (formerly Azure AD) as an IdP are susceptib...7.1
- CVE-2026-22050ONTAP versions 9.16.1 prior to 9.16.1P9 and 9.17.1 prior to 9.17.1P2 with snapshot locking enabled are susceptible to a vulnerability which could allow a privileged remote attacker to set the snaps...4.3
- CVE-2025-26517CVE-2025-26517 Privilege Escalation Vulnerability in StorageGRID (formerly StorageGRID Webscale)5.4
- CVE-2025-26516CVE-2025-26516 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)5.3
- CVE-2025-26515CVE-2025-26515 Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Webscale)7.5
- CVE-2025-26514CVE-2025-26514 Reflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale)6.4
- CVE-2025-26513The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when successfully exploited could allow a local user to escalate their privileges.7.0
- CVE-2025-27820Apache HttpComponents: PSL (Public Suffix List) validation bypass7.5
- CVE-2025-30722Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit ...5.3
The record
- Peak rank
- #3 in Oct 2021
- Busiest month shown
- Jan 2022, 105 CVEs
- Months with a KEV entry
- 19 since Sep 2019
- Monthly snapshots
- 90 since 2008