NetApp products contain multiple vulnerabilities enabling remote denial of service, data…
NetApp products contain multiple vulnerabilities enabling remote denial of service, data confidentiality breaches, and data integrity attacks.
The French CERT has published an advisory detailing multiple vulnerabilities affecting several NetApp enterprise products. The affected systems include Active IQ Unified Manager across multiple platforms (Linux, Windows, VMware vSphere) prior to version 9.18P1, Brocade SAN Navigator (SANnav) versions before v2.3.1, and ONTAP tools for VMware vSphere 10 versions prior to 10.3. These vulnerabilities enable attackers to perform remote denial of service attacks, compromise data confidentiality, and affect data integrity.
The advisory references seven distinct CVEs spanning from 2023 through 2025, along with corresponding NetApp security bulletins published on May 27, 2026. The vulnerabilities impact critical enterprise storage management and SAN monitoring infrastructure. NetApp has released patches addressing these issues, and organizations running affected versions should consult the vendor bulletins for remediation guidance.
Given the enterprise nature of the affected products and the potential for data confidentiality and integrity impacts in storage management systems, organizations using NetApp infrastructure should prioritize patching efforts. The advisory provides links to multiple NetApp security bulletins and CVE records for detailed technical information.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0671
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free