{"schema_version":1,"title":"NetApp vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in NetApp: 0 in the last 7 days and 2 in the last 90 days, 5 of them critical and 3 exploited in the wild. The most recent, CVE-2026-22056, was published on 28 August 2026. 12 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/netapp","json_url":"https://junglewise.ai/threats/vendors/netapp.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/netapp","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":4,"all_time":17,"critical":5,"exploited":3,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":5},"latest":[{"cve":"CVE-2026-22056","epss":0.0025,"slug":"cve-2026-22056-netapp-storagegrid-denial-of-service-in-non-standard","title":"NetApp StorageGRID denial of service in non-standard configuration","severity":"info","exploited":false,"published_at":"2026-08-28T22:16:47.883+00:00","url":"https://junglewise.ai/threats/cve-2026-22056-netapp-storagegrid-denial-of-service-in-non-standard"},{"cve":"CVE-2026-22049","cvss":8.7,"slug":"cve-2026-22049-netapp-ontap-mfa-bypass-in-webauthn","title":"NetApp ONTAP MFA bypass in WebAuthn","severity":"info","exploited":false,"published_at":"2026-07-22T19:16:59.82+00:00","url":"https://junglewise.ai/threats/cve-2026-22049-netapp-ontap-mfa-bypass-in-webauthn"},{"cve":"CVE-2026-22055","cvss":5.3,"slug":"cve-2026-22055-netapp-active-iq-onecollect-hard-coded-credentials-in-autosupport","title":"NetApp Active IQ OneCollect hard-coded credentials in AutoSupport","severity":"info","exploited":false,"published_at":"2026-06-03T22:16:34.49+00:00","url":"https://junglewise.ai/threats/cve-2026-22055-netapp-active-iq-onecollect-hard-coded-credentials-in-autosupport"},{"cve":"CVE-2026-22054","cvss":5.3,"slug":"cve-2026-22054-netapp-active-iq-config-advisor-hard-coded-credentials-in","title":"NetApp Active IQ Config Advisor hard-coded credentials in AutoSupport","severity":"info","exploited":false,"published_at":"2026-06-03T22:16:34.343+00:00","url":"https://junglewise.ai/threats/cve-2026-22054-netapp-active-iq-config-advisor-hard-coded-credentials-in"},{"cve":"CVE-2026-22051","cvss":4.3,"epss":0.0025,"slug":"cve-2026-22051-netapp-storagegrid-information-disclosure-via-arbitrary-metrics","title":"NetApp StorageGRID information disclosure via arbitrary metrics queries","severity":"medium","exploited":false,"published_at":"2026-04-20T22:16:23.367+00:00","url":"https://junglewise.ai/threats/cve-2026-22051-netapp-storagegrid-information-disclosure-via-arbitrary-metrics"},{"cve":"CVE-2024-54085","cvss":10,"epss":0.4297,"slug":"cve-2024-54085-ami-megarac-spx-authentication-bypass-in-redfish-host-interface","title":"AMI MegaRAC SPx authentication bypass in Redfish Host Interface","severity":"critical","exploited":true,"published_at":"2025-06-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-54085-ami-megarac-spx-authentication-bypass-in-redfish-host-interface"},{"cve":"CVE-2024-38475","cvss":9.1,"slug":"cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability","title":"Apache HTTP Server Improper Escaping of Output Vulnerability","severity":"critical","exploited":true,"published_at":"2025-05-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability"},{"cve":"CVE-2025-0411","cvss":7,"slug":"cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability","title":"7-Zip Mark of the Web Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-06T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability"},{"cve":"CVE-2024-3447","cvss":6,"slug":"cve-2024-3447-qemu-heap-buffer-overflow-in-sdhci-device-emulation","title":"QEMU heap buffer overflow in SDHCI device emulation","severity":"medium","exploited":false,"published_at":"2024-11-14T12:15:17.743+00:00","url":"https://junglewise.ai/threats/cve-2024-3447-qemu-heap-buffer-overflow-in-sdhci-device-emulation"},{"cve":"CVE-2024-33601","cvss":7.3,"slug":"cve-2024-33601-gnu-glibc-denial-of-service-in-nscd-netgroup-cache","title":"GNU glibc denial of service in nscd netgroup cache","severity":"high","exploited":false,"published_at":"2024-05-06T20:15:11.603+00:00","url":"https://junglewise.ai/threats/cve-2024-33601-gnu-glibc-denial-of-service-in-nscd-netgroup-cache"},{"cve":"CVE-2024-33600","cvss":5.9,"slug":"cve-2024-33600-gnu-glibc-null-pointer-dereference-in-nscd-netgroup-cache","title":"GNU glibc null pointer dereference in nscd netgroup cache","severity":"medium","exploited":false,"published_at":"2024-05-06T20:15:11.523+00:00","url":"https://junglewise.ai/threats/cve-2024-33600-gnu-glibc-null-pointer-dereference-in-nscd-netgroup-cache"},{"cve":"CVE-2024-33599","cvss":8.1,"slug":"cve-2024-33599-gnu-glibc-nscd-stack-based-buffer-overflow-in-netgroup-cache","title":"GNU glibc nscd stack-based buffer overflow in netgroup cache","severity":"high","exploited":false,"published_at":"2024-05-06T20:15:11.437+00:00","url":"https://junglewise.ai/threats/cve-2024-33599-gnu-glibc-nscd-stack-based-buffer-overflow-in-netgroup-cache"},{"cve":"CVE-2023-28531","cvss":9.8,"slug":"cve-2023-28531-openssh-ssh-add-destination-constraint-bypass-for-smartcard-keys","title":"OpenSSH ssh-add destination constraint bypass for smartcard keys","severity":"critical","exploited":false,"published_at":"2023-03-17T04:15:14.553+00:00","url":"https://junglewise.ai/threats/cve-2023-28531-openssh-ssh-add-destination-constraint-bypass-for-smartcard-keys"},{"cve":"CVE-2022-43945","cvss":7.5,"slug":"cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling","title":"Linux Kernel NFSD buffer overflow in RPC handling","severity":"high","exploited":false,"published_at":"2022-11-04T19:15:11.18+00:00","url":"https://junglewise.ai/threats/cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling"},{"cve":"CVE-2021-38202","cvss":7.5,"slug":"cve-2021-38202-linux-kernel-out-of-bounds-read-in-nfsd-tracepoint","title":"Linux Kernel out-of-bounds read in nfsd tracepoint","severity":"high","exploited":false,"published_at":"2021-08-08T20:15:07.18+00:00","url":"https://junglewise.ai/threats/cve-2021-38202-linux-kernel-out-of-bounds-read-in-nfsd-tracepoint"},{"cve":"CVE-2016-10160","cvss":9.8,"slug":"cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile","title":"PHP off-by-one error in phar_parse_pharfile","severity":"critical","exploited":false,"published_at":"2017-01-24T21:59:00.227+00:00","url":"https://junglewise.ai/threats/cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile"},{"cve":"CVE-1999-0016","cvss":5,"slug":"cve-1999-0016-multiple-vendors-tcp-ip-land-denial-of-service","title":"Multiple Vendors TCP/IP Land denial of service","severity":"medium","exploited":false,"published_at":"1997-12-01T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0016-multiple-vendors-tcp-ip-land-denial-of-service"}],"vendor":{"hub":true,"name":"NetApp","slug":"netapp","homepage":"https://www.netapp.com/","description":"An American hybrid cloud data services and data management company.","url":"https://junglewise.ai/threats/vendors/netapp"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2024-54085","cvss":10,"epss":0.4297,"slug":"cve-2024-54085-ami-megarac-spx-authentication-bypass-in-redfish-host-interface","title":"AMI MegaRAC SPx authentication bypass in Redfish Host Interface","severity":"critical","exploited":true,"published_at":"2025-06-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-54085-ami-megarac-spx-authentication-bypass-in-redfish-host-interface"},{"cve":"CVE-2024-38475","cvss":9.1,"slug":"cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability","title":"Apache HTTP Server Improper Escaping of Output Vulnerability","severity":"critical","exploited":true,"published_at":"2025-05-01T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38475-apache-http-server-improper-escaping-of-output-vulnerability"},{"cve":"CVE-2025-0411","cvss":7,"slug":"cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability","title":"7-Zip Mark of the Web Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2025-02-06T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-0411-7-zip-mark-of-the-web-bypass-vulnerability"},{"cve":"CVE-2023-28531","cvss":9.8,"slug":"cve-2023-28531-openssh-ssh-add-destination-constraint-bypass-for-smartcard-keys","title":"OpenSSH ssh-add destination constraint bypass for smartcard keys","severity":"critical","exploited":false,"published_at":"2023-03-17T04:15:14.553+00:00","url":"https://junglewise.ai/threats/cve-2023-28531-openssh-ssh-add-destination-constraint-bypass-for-smartcard-keys"},{"cve":"CVE-2016-10160","cvss":9.8,"slug":"cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile","title":"PHP off-by-one error in phar_parse_pharfile","severity":"critical","exploited":false,"published_at":"2017-01-24T21:59:00.227+00:00","url":"https://junglewise.ai/threats/cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile"},{"cve":"CVE-2024-33599","cvss":8.1,"slug":"cve-2024-33599-gnu-glibc-nscd-stack-based-buffer-overflow-in-netgroup-cache","title":"GNU glibc nscd stack-based buffer overflow in netgroup cache","severity":"high","exploited":false,"published_at":"2024-05-06T20:15:11.437+00:00","url":"https://junglewise.ai/threats/cve-2024-33599-gnu-glibc-nscd-stack-based-buffer-overflow-in-netgroup-cache"},{"cve":"CVE-2022-43945","cvss":7.5,"slug":"cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling","title":"Linux Kernel NFSD buffer overflow in RPC handling","severity":"high","exploited":false,"published_at":"2022-11-04T19:15:11.18+00:00","url":"https://junglewise.ai/threats/cve-2022-43945-linux-kernel-nfsd-buffer-overflow-in-rpc-handling"},{"cve":"CVE-2021-38202","cvss":7.5,"slug":"cve-2021-38202-linux-kernel-out-of-bounds-read-in-nfsd-tracepoint","title":"Linux Kernel out-of-bounds read in nfsd tracepoint","severity":"high","exploited":false,"published_at":"2021-08-08T20:15:07.18+00:00","url":"https://junglewise.ai/threats/cve-2021-38202-linux-kernel-out-of-bounds-read-in-nfsd-tracepoint"},{"cve":"CVE-2024-33601","cvss":7.3,"slug":"cve-2024-33601-gnu-glibc-denial-of-service-in-nscd-netgroup-cache","title":"GNU glibc denial of service in nscd netgroup cache","severity":"high","exploited":false,"published_at":"2024-05-06T20:15:11.603+00:00","url":"https://junglewise.ai/threats/cve-2024-33601-gnu-glibc-denial-of-service-in-nscd-netgroup-cache"},{"cve":"CVE-2024-3447","cvss":6,"slug":"cve-2024-3447-qemu-heap-buffer-overflow-in-sdhci-device-emulation","title":"QEMU heap buffer overflow in SDHCI device emulation","severity":"medium","exploited":false,"published_at":"2024-11-14T12:15:17.743+00:00","url":"https://junglewise.ai/threats/cve-2024-3447-qemu-heap-buffer-overflow-in-sdhci-device-emulation"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[{"name":"NetApp H300S Firmware","slug":"h300s-firmware","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/h300s-firmware"},{"name":"NetApp H410C Firmware","slug":"h410c-firmware","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/h410c-firmware"},{"name":"NetApp H410S Firmware","slug":"h410s-firmware","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/h410s-firmware"},{"name":"NetApp H500S Firmware","slug":"h500s-firmware","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/h500s-firmware"},{"name":"NetApp H700S Firmware","slug":"h700s-firmware","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/h700s-firmware"},{"name":"NetApp Hci Bootstrap Os","slug":"hci-bootstrap-os","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/hci-bootstrap-os"},{"name":"NetApp H300s","slug":"h300s","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/h300s"},{"name":"NetApp H410c","slug":"h410c","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/h410c"},{"name":"NetApp H410s","slug":"h410s","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/h410s"},{"name":"NetApp H500s","slug":"h500s","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/h500s"},{"name":"NetApp H700s","slug":"h700s","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/h700s"},{"name":"NetApp HCI Compute Node","slug":"hci-compute-node","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/hci-compute-node"}]}