# NetApp ONTAP 9 vulnerability patched

Published: 2026-09-17 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/9ebf0272-9197-5bf1-93c6-0e5f183fe72d/netapp-ontap-9-vulnerability-patched

> CERT-FR advises patching NetApp ONTAP 9 for a flaw enabling remote DoS, data confidentiality and integrity breaches.

CERT-FR published an advisory covering a vulnerability in NetApp ONTAP 9, tracked as CVE-2026-42512. The flaw affects multiple ONTAP 9 version branches (9.1.16.x, 9.15.x, 9.17.x, 9.18.x, and 9.19.x) prior to specific patched releases, and could allow an attacker to cause a remote denial of service, as well as breach data confidentiality and integrity.

No evidence of active exploitation is mentioned in the advisory. Organizations running affected ONTAP 9 versions should consult NetApp's security bulletin (NTAP-20260501-0006) and apply the referenced patches (9.16.1P14, 9.15.1P20, 9.17.1P10, 9.18.1P5, or upgrade to 9.19.1 as applicable) to remediate the issue.

## Mentioned in this report

- Vulnerabilities: CVE-2026-42512

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1194

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9ebf0272-9197-5bf1-93c6-0e5f183fe72d/netapp-ontap-9-vulnerability-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
