NetApp, Inc.
First CVE: Nov 10, 2017Active for: 9 years
133
CVEs Published
More CVEs Published than 74% of tracked CNAs
13.3
Avg CVEs / Year
More Avg CVEs / Year than 61% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by NetApp, Inc. as a CNA, 96.2% affect products that NetApp, Inc. develops as a vendor.
96.2%
Self-reported: 128Third-party: 5
Of all the CVEs published that affect products developed by NetApp, Inc., 5.1% are self-published by NetApp, Inc. as a CNA.
94.9%
Self-published: 128Published by other CNAs: 2,383
Trends Over Time
The number and severity of CVEs published by NetApp, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2017
8 years ago
Most Recent CVE
Jul 22, 2026
2 days ago
Top CVEs
All CVEs published by NetApp, Inc. as a CNA, regardless of affected vendor or product.
133 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22049HIGH ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successful | Jul 22, 2026 | 8.7 | 36 | NO | NO |
CVE-2026-22054HIGH Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations | Jun 3, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-22055HIGH Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. | Jun 3, 2026 | 8.8 | 35 | NO | NO |
CVE-2019-5497CRITICAL NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command | Jul 1, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-5490CRITICAL Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary | Mar 21, 2019 | 9.8 | 32 | NO | NO |
CVE-2025-26512CRITICAL SnapCenter versions prior to
6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an
authenticated SnapCenter Server user to become an admin user on a remote
sys | Mar 24, 2025 | 9.9 | 31 | NO | NO |
CVE-2023-1096CRITICAL SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user | May 12, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-27007CRITICAL NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to | Dec 23, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-5487CRITICAL NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are | May 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-26987CRITICAL Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploi | Mar 15, 2021 | 9.8 | 30 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA133 CVEs
44%
38%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (16.5%)
Network106 (79.7%)
Unknown0 (0.0%)
Physical1 (0.8%)
Adjacent Network4 (3.0%)
Attack Complexity
Low124 (93.2%)
High9 (6.8%)
Unknown0 (0.0%)
User Interaction
None123 (92.5%)
Unknown0 (0.0%)
Required10 (7.5%)
Privileges Required
Low56 (42.1%)
High10 (7.5%)
None67 (50.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (133 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by NetApp, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by NetApp, Inc. as a CNA — matched by CVE ID, not by organization name.