NetApp ONTAP 9 vulnerability enables DoS
A vulnerability in NetApp ONTAP 9 allows a remote attacker to cause denial of service and compromise data integrity.
CERT-FR published an advisory regarding a vulnerability in NetApp ONTAP 9 storage operating system, tracked as CVE-2026-35547. The flaw affects ONTAP 9.13.x versions prior to 9.13.1P21 and 9.17.x versions prior to 9.17.1P9, allowing a remote attacker to trigger a denial of service condition and impact data integrity on affected systems.
NetApp has released a security bulletin (NTAP-20260501-0002) with patched versions addressing the issue. Organizations running affected ONTAP versions should apply the vendor-provided fixes. No evidence of active exploitation is mentioned in the advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0857
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free