NetApp ONTAP 9 Flaw Patched by Vendor
A vulnerability in NetApp ONTAP 9 can let an attacker cause denial of service and compromise data confidentiality and integrity.
ANSSI (CERT-FR) issued an advisory covering a vulnerability in NetApp's ONTAP 9 storage operating system, tracked as CVE-2026-42511. The flaw affects multiple ONTAP 9 release branches, including 9.16.x prior to 9.16.1P14, 9.18.x prior to 9.18.1P5, and 9.19.x prior to 9.19.1.
Exploitation of the vulnerability could allow a remote attacker to cause a denial of service condition, as well as compromise the confidentiality and integrity of data handled by affected systems. NetApp has published a corresponding security bulletin (NTAP-20260501-0005) detailing the issue and providing patched versions. No evidence of active exploitation is mentioned in the advisory; organizations running affected ONTAP versions are advised to apply the vendor-provided fixes.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0923
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free