# NetApp ONTAP 9 vulnerability enables DoS

Published: 2026-07-10 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/2cfd5316-463b-5764-9653-4b65b8cdf31f/netapp-ontap-9-vulnerability-enables-dos

> A vulnerability in NetApp ONTAP 9 allows a remote attacker to cause denial of service and compromise data integrity.

CERT-FR published an advisory regarding a vulnerability in NetApp ONTAP 9 storage operating system, tracked as CVE-2026-35547. The flaw affects ONTAP 9.13.x versions prior to 9.13.1P21 and 9.17.x versions prior to 9.17.1P9, allowing a remote attacker to trigger a denial of service condition and impact data integrity on affected systems.

NetApp has released a security bulletin (NTAP-20260501-0002) with patched versions addressing the issue. Organizations running affected ONTAP versions should apply the vendor-provided fixes. No evidence of active exploitation is mentioned in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-35547

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0857

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2cfd5316-463b-5764-9653-4b65b8cdf31f/netapp-ontap-9-vulnerability-enables-dos.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
