NetApp ONTAP 9 vulnerability patched
CERT-FR advises patching NetApp ONTAP 9 for a flaw enabling remote DoS, data confidentiality and integrity breaches.
CERT-FR published an advisory covering a vulnerability in NetApp ONTAP 9, tracked as CVE-2026-42512. The flaw affects multiple ONTAP 9 version branches (9.1.16.x, 9.15.x, 9.17.x, 9.18.x, and 9.19.x) prior to specific patched releases, and could allow an attacker to cause a remote denial of service, as well as breach data confidentiality and integrity.
No evidence of active exploitation is mentioned in the advisory. Organizations running affected ONTAP 9 versions should consult NetApp's security bulletin (NTAP-20260501-0006) and apply the referenced patches (9.16.1P14, 9.15.1P20, 9.17.1P10, 9.18.1P5, or upgrade to 9.19.1 as applicable) to remediate the issue.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1194
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free