Vendor
NetApp vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in NetApp: 0 in the last 7 days and 2 in the last 90 days, 5 of them critical and 3 exploited in the wild. The most recent, CVE-2026-22056, was published on 28 August 2026. 12 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 5
- Exploited in the wild
- 3
About NetApp
An American hybrid cloud data services and data management company.
NetApp technologies
Latest NetApp vulnerabilities
- CVE-2026-22056: NetApp StorageGRID denial of service in non-standard configurationinfoEPSS 0.3%
- CVE-2026-22049: NetApp ONTAP MFA bypass in WebAuthninfoCVSS 8.7
- CVE-2026-22055: NetApp Active IQ OneCollect hard-coded credentials in AutoSupportinfoCVSS 5.3
- CVE-2026-22054: NetApp Active IQ Config Advisor hard-coded credentials in AutoSupportinfoCVSS 5.3
- CVE-2026-22051: NetApp StorageGRID information disclosure via arbitrary metrics queriesmediumCVSS 4.3EPSS 0.3%
- CVE-2024-54085: AMI MegaRAC SPx authentication bypass in Redfish Host Interfacecriticalexploited in the wildCVSS 10EPSS 43.0%
- CVE-2024-38475: Apache HTTP Server Improper Escaping of Output Vulnerabilitycriticalexploited in the wildCVSS 9.1
- CVE-2025-0411: 7-Zip Mark of the Web Bypass Vulnerabilitycriticalexploited in the wildCVSS 7
- CVE-2024-3447: QEMU heap buffer overflow in SDHCI device emulationmediumCVSS 6
- CVE-2024-33601: GNU glibc denial of service in nscd netgroup cachehighCVSS 7.3
- CVE-2024-33600: GNU glibc null pointer dereference in nscd netgroup cachemediumCVSS 5.9
- CVE-2024-33599: GNU glibc nscd stack-based buffer overflow in netgroup cachehighCVSS 8.1
- CVE-2023-28531: OpenSSH ssh-add destination constraint bypass for smartcard keyscriticalCVSS 9.8
- CVE-2022-43945: Linux Kernel NFSD buffer overflow in RPC handlinghighCVSS 7.5
- CVE-2021-38202: Linux Kernel out-of-bounds read in nfsd tracepointhighCVSS 7.5
- CVE-2016-10160: PHP off-by-one error in phar_parse_pharfilecriticalCVSS 9.8
- CVE-1999-0016: Multiple Vendors TCP/IP Land denial of servicemediumCVSS 5
Most severe NetApp vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-54085: AMI MegaRAC SPx authentication bypass in Redfish Host Interfacecriticalexploited in the wildCVSS 10EPSS 43.0%
- CVE-2024-38475: Apache HTTP Server Improper Escaping of Output Vulnerabilitycriticalexploited in the wildCVSS 9.1
- CVE-2025-0411: 7-Zip Mark of the Web Bypass Vulnerabilitycriticalexploited in the wildCVSS 7
- CVE-2023-28531: OpenSSH ssh-add destination constraint bypass for smartcard keyscriticalCVSS 9.8
- CVE-2016-10160: PHP off-by-one error in phar_parse_pharfilecriticalCVSS 9.8
- CVE-2024-33599: GNU glibc nscd stack-based buffer overflow in netgroup cachehighCVSS 8.1
- CVE-2022-43945: Linux Kernel NFSD buffer overflow in RPC handlinghighCVSS 7.5
- CVE-2021-38202: Linux Kernel out-of-bounds read in nfsd tracepointhighCVSS 7.5
- CVE-2024-33601: GNU glibc denial of service in nscd netgroup cachehighCVSS 7.3
- CVE-2024-3447: QEMU heap buffer overflow in SDHCI device emulationmediumCVSS 6
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/netapp.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "NetApp vulnerabilities", https://junglewise.ai/threats/vendors/netapp, 28 September 2026.