Is ONTAP 9 releases affected by CVE-2026-59995 OpenSSH vulnerabilities
Applies to
- NetApp ONTAP 9.x and later
- CVE-2026-59995
- CVE-2026-59996
- CVE-2026-59997
- CVE-2026-59998
- CVE-2026-59999
- CVE-2026-60000
- CVE-2026-60001
- CVE-2026-60002
- OpenSSH Vulnerability
Answer
- According to the Security advisory, current ONTAP versions are not affected by the listed OpenSSH version prior to 10.4 client-side vulnerabilities.
- The SSH server in ONTAP is not impacted, and SFTP operations from ONTAP require BSD shell access, which makes the exploitability status Not Exploitable.
- The OpenSSH version in ONTAP cannot be updated independently. For authoritative information, refer to NetApp's public security advisories
Additional Information
- Reference the following Public Report for versions of ONTAP that will contain OpenSSH 10.4
